Valve is notifying European Steam hardware customers about a data breach at its shipping partner, CEVA Logistics.
The breach exposed delivery-related customer data. However, it did not expose Steam passwords, payment card details or Steam Guard codes.
The Valve data breach could still help criminals create convincing phishing scams. Affected customers should be cautious with unexpected delivery messages.
Attack hit Steam shipping partner
CEVA Logistics ships Steam hardware orders to customers across Europe. Valve said attackers accessed CEVA systems between July 29 and August 1.
Valve learned about the breach on August 7. It has begun notifying customers who may have been affected.
CEVA receives limited order information from Steam to complete deliveries. It keeps that information for up to 90 days after an order.
The company is part of the CMA CGM Group. It operates around 1,000 warehouses and handled 15 million shipments last year.
Customer delivery information exposed
The stolen data may include names, postal addresses, phone numbers and email addresses. It may also include the type and price of ordered Steam hardware.
Valve said CEVA cannot access payment details or Steam account passwords. It also cannot access Steam Guard codes or other sensitive account data.
Therefore, affected customers do not need to reset their Steam passwords. They also do not need to change account settings because of this incident alone.
However, the Valve data breach still creates a phishing risk. Stolen order details can make fraudulent messages seem more believable.
Valve warns of phishing messages
Valve warned that customers could receive fake emails, text messages or calls. The messages may claim to come from Steam, Valve or a delivery company.
Scammers may quote an address or order detail to appear genuine. They may also ask customers to confirm a delivery or pay a small fee.
Other messages may direct customers to a fake sign-in page. Valve said customers should treat these requests as suspicious.
People should avoid unsolicited links and payment requests. They should also avoid sharing account credentials over email, text or phone.
CEVA isolates affected systems
CEVA has isolated the affected systems and taken them offline. The company has also brought in external investigators.
Valve said it is seeking more details about the attack. It is also notifying data-protection authorities in affected countries.
The incident follows a separate cyberattack disclosed by CEVA on August 1. That earlier attack disrupted operations at eight European warehouses.
The Valve data breach highlights supply-chain security risks. A breach at a delivery partner can still expose customer information.


0 responses to “Valve Notifies Steam Hardware Customers of Data Breach”