Key Takeaways:
- Hackers accessed CEVA Logistics servers, resulting in a Steam customer data breach that exposed European customer information.
- Stolen data includes names, addresses, phone numbers, emails, and purchases.
- Valve warns customers about phishing attempts using compromised delivery information.
Valve notified Steam hardware customers in Europe Aug. 10 that hackers stole delivery information after attacking CEVA Logistics, its shipping partner, between July 29 and Aug. 1.
Hackers Access CEVA Systems And Steal Customer Data
Hackers gained access to CEVA Logistics servers between July 29 and Aug. 1, according to Valve’s notification to affected customers, leading to a Steam customer data breach that exposed information CEVA uses to deliver physical Steam hardware orders in Europe.
Valve said it learned of the possible compromise Aug. 7 and began notifying customers it believed could have been affected. CEVA retains delivery information for up to 90 days after an order, according to Valve’s notification.
The stolen information includes customers’ names, addresses, phone numbers and email addresses. It also includes the type and price of the hardware products they ordered.
Valve said the Steam customer data breach did not expose additional Steam account or purchase information. CEVA does not have access to payment information, passwords, Steam Guard codes, or other sensitive Steam account data.
Valve Warns Customers About Phishing Attempts
Valve warned affected customers that the Steam customer data breach could enable attackers to use the stolen information in email, SMS, or voice phishing attempts. The attackers could pretend to represent Steam, Valve, or a delivery company when contacting customers.
The company said scammers could use real delivery information to make their messages appear legitimate. They may repeat a customer’s address, ask the person to confirm a delivery, request a small customs or redelivery payment, or ask the customer to sign in to verify an order.
Valve told customers to treat such messages as fake. It also said customers do not need to change their Steam passwords or account settings because of the incident.
The warning focuses on the risk created by the exposed delivery information rather than a compromise of Steam’s own account systems. Valve said the stolen data did not include the sensitive account information held outside CEVA’s delivery records.
CEVA Investigates As Valve Notifies Authorities
Valve said it is pressing CEVA for more information about the full scope of the Steam customer data breach and how the data was taken. The company also said it is notifying data protection authorities in affected countries.
CEVA has isolated the affected systems and taken them offline, while outside investigators have been brought in to examine the attack. The investigation is still focused on determining what information was taken and how the attackers accessed it.
The Steam customer data breach followed a cyberattack that CEVA reported to multiple European retailers Aug. 1. The attack disrupted operations at eight of CEVA’s European warehouses, according to the report.
The incident affects Steam customers whose hardware delivery information was held by CEVA in Europe. Valve’s notification makes clear that the exposed information was tied to hardware shipments, while payment details, passwords, and Steam Guard codes were not accessible to CEVA.
Valve did not provide a final count of affected customers in its notification about the Steam customer data breach.
Visit CyberPro Magazine For The Most Recent Information.




