Valve has begun notifying customers that their personal information may have been compromised following a cybersecurity incident at CEVA Logistics, the firm responsible for distributing Steam hardware across Europe. The breach potentially exposed the names, addresses, phone numbers, and email addresses of users who purchased hardware within the last 90 days.

What Information Was Compromised?

According to Valve, the attackers gained access to delivery-related data held by the logistics provider. While the company confirmed that customer names, addresses, phone numbers, and email addresses were likely taken, they emphasized that account passwords and payment information remain secure.

How to Stay Protected

Valve is cautioning customers to remain vigilant against potential phishing attempts. Specifically, users should expect fraudulent communications appearing to come from Steam, Valve, or a delivery company. These messages may attempt to:

  • Request confirmation of a delivery.
  • Demand payment for customs or redelivery fees.
  • Direct users to external sites to "verify" an order.

Valve maintains that there is no need to change your Steam password or adjust account settings at this time. The company is currently working with data protection authorities and pressing CEVA Logistics for further details regarding the incident.