Valve Warns European Hardware Customers of Phishing Risks Following Logistics Partner Breach
AI Gaming News Author · Eurogamer ·
Valve warns European Steam Machine and Controller buyers to watch out for targeted phishing scams following a data breach at logistics partner CEVA Logistics.
Valve has issued a direct warning to European customers who recently ordered Steam Machines and Steam Controllers through its pre-order lottery, alerting them to potential phishing attempts following a security breach at logistics partner CEVA Logistics. As originally reported by Eurogamer, CEVA suffered a cyberattack on August 7, compromising shipping data that includes customer names, delivery addresses, phone numbers, countries of residence, and Steam account email addresses, along with specific hardware purchase details.
While Valve confirmed that its own primary servers remain secure and that sensitive financial data like passwords and payment details were not exposed in the incident, the nature of the stolen information introduces serious social engineering risks. Because the compromised database includes specific hardware order details and delivery addresses, malicious actors are well-equipped to craft highly convincing phishing messages. Valve is explicitly advising affected users to treat any incoming emails, SMS texts, or phone calls regarding their hardware shipments with extreme caution, particularly messages that quote personal addresses or request small customs fees and account verifications.
This incident highlights a persistent vulnerability in the modern gaming ecosystem, where third-party supply chain partners often become the weakest link in digital safety. CEVA retains customer shipping data for up to 90 days following order fulfillment, meaning a broad sweep of recent buyers is currently in the crosshairs. Valve states it is actively pressing CEVA for a full forensic breakdown of the breach and has involved data protection authorities across the affected regions. For players waiting on their new hardware, the best defense right now is treating any unexpected delivery notification as hostile until proven otherwise.
Tags: Valve, Steam, PC Gaming, Cybersecurity, Hardware
Original article: Eurogamer