Valve says attackers did not access the system that processed European Steam hardware orders during a cyberattack on CEVA Logistics. However, the company still warns customers to remain alert for convincing delivery scams.

Valve Withdraws Earlier Data Exposure Warning

Valve previously notified European Steam hardware customers that the CEVA Logistics cyberattack may have exposed their personal information.

The potentially affected records included customer names, addresses, contact details and order histories. However, passwords, payment information and Steam Guard codes were never part of the suspected exposure.

Valve has now issued a follow-up notice after receiving additional information from CEVA.

The logistics company has not completed its full investigation. Nevertheless, it determined that the attack affected only a limited group of internal systems.

Crucially, the system used to process Steam hardware orders was not among them. Valve said it currently has no indication that attackers could access the relevant customer information at any point.

The company also apologised for the delay and for any concern caused by its original warning.

Customers Should Still Expect Phishing Attempts

Despite the reassuring update, Valve continues to advise customers to remain cautious about messages concerning hardware orders.

Scammers may send emails or text messages that appear to come from Valve, Steam or a delivery company. They could also contact customers by phone.

Fraudulent messages may ask the recipient to confirm a delivery or pay a small customs or redelivery charge. Some could direct users to a fake sign-in page that claims to verify an order.

Valve warned that scammers might quote a customer’s address to make the communication appear legitimate. The company recommends treating all unexpected order-related messages as fraudulent.

Customers should avoid opening suspicious links or providing account credentials. They should also verify delivery information through official services instead of responding directly to an unsolicited message.

CEVA Attack Affected Other Organisations

CEVA Logistics operates more than 1,300 locations worldwide and employs over 110,000 people. The global logistics and supply chain company generated more than $18.3 billion in revenue last year.

Several businesses warned customers about possible data theft following the incident in August.

The affected organisations included Dutch department store De Bijenkorf and online retailer bol. Football club Ajax, financial institution ING and optician chain Ace & Tate also issued warnings.

The Pokémon Center reported potential exposure linked to the same logistics provider as well.

CEVA later confirmed that attackers stole personal information belonging to current and former employees. That data included identification documents, Social Security numbers and bank details.

The compromised employee records also contained salary information, family details and absence records.

No Evidence Valve Customer Data Was Accessible

The latest update indicates that Steam hardware buyers were not part of the confirmed data exposure. However, CEVA’s wider investigation remains ongoing.

Valve customer data such as passwords and payment information was never thought to be involved. The company now says the system containing order details also remained outside the affected environment.

European Steam shoppers can therefore feel more confident that the attackers did not access their order records. Still, Valve’s phishing warning remains relevant because criminals frequently exploit public breach reports to create believable scams.


0 responses to “Valve Says Customer Data Was Safe in CEVA Cyberattack”