Valve has issued a warning to Steam Machine and Steam Controller customers in Europe after its logistics partner, CEVA Logistics, suffered a cyberattack between July 29 and August 1. CEVA notified Valve on August 7, and Valve has since begun contacting affected customers directly.
The breach did not touch Valve's own servers, and payment information, passwords, and Steam Guard codes are confirmed safe. What was likely taken is everything else a shipping partner would hold, including customer names, home addresses, postal codes, phone numbers, Steam account email addresses, and hardware purchase details, including the type and price of the ordered product. CEVA stores delivery-related information for up to 90 days after an order, which is why Valve is notifying all customers it can assume were impacted within that window.

A bad actor who knows your details and that you recently ordered a Steam Machine or Steam Controller has everything needed to craft a convincing phishing message. Valve's warning is to "Expect fake messages, email, SMS or phone, that mention your hardware order and come from Steam, Valve or a delivery company. They may quote your address back to you to prove they're genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to verify your order. Treat all of them as fake."

Valve has also reminded customers of three things that are always true. Steam Support only handles account issues at help.steampowered.com and never through email, Steam Chat, or Discord. Every real Steam login page is on one of four official domains. And Steam Support will never ask for a password or Steam Guard code.

Frequently Asked Questions
TweakBot answers common questions about this news using TweakTown's own coverage from this page and related content from our archive. All answers are generated from TweakTown content and not outside sources. Tap a question to reveal the answer, or type your own below related to this content.
How long does CEVA retain delivery-related information, and why is Valve notifying customers within that retention window?
How can customers contact Valve or the designated contact point if they have questions about the breach?
What steps has Valve reported taking in response to the CEVA breach (e.g., notifications, isolating systems, pressing CEVA)?
Have a question about this content not listed here? Ask below and TweakBot will answer it.
Valve says it is pressing CEVA for the full scope of what was taken, has isolated the affected systems, and is in the process of notifying data protection authorities across affected countries. Anyone with questions can reach Valve through its support site or through the designated contact point, Artana Digital GmbH in Hamburg.






