Valve is warning European players who bought a Steam Machine or Steam Controller to expect phishing attempts. A cyberattack on CEVA Logistics may have exposed personal and order information, although passwords, Steam Guard codes and payment details were not stolen.
The company contacted affected customers by email after its European Steam hardware distribution partner was hacked. The compromised information could be used to create highly convincing personalized messages, so buyers should treat any communication about deliveries, fees or order changes with particular caution.
The attack on CEVA Logistics and the data involved
According to Valve’s notice, the intrusion took place between July 29 and August 1 and was limited to CEVA Logistics. Steam’s own systems were not breached, but attackers probably obtained some details belonging to customers who ordered Steam hardware in recent months.
The potentially exposed records include names, full addresses with postal code, city and country, phone numbers, the email address used for Steam, and the type and price of the purchased product. CEVA keeps this material for up to 90 days after an order, meaning that many European launch-period buyers could be affected.
Valve stresses that the logistics company cannot access payment data, Steam passwords, Steam Guard codes or other account-security credentials. Users therefore do not need to change their passwords or alter their Steam settings because of this incident.
Valve is demanding a detailed account from CEVA Logistics of how the attack occurred and precisely which information was taken. It will also cooperate with data-protection authorities in the relevant European countries. CEVA has isolated the affected systems, disconnected them from the network and brought in external investigators.
The one recommendation: distrust every message
The stolen information can support phishing emails, text messages and phone calls that appear genuine. Valve expects scammers to pose as Steam, Valve or delivery companies and possibly quote the customer’s real address to make the approach more believable.
“They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign something to ‘verify’ your order. Treat all of these as fake,” the company warns. Steam Support handles accounts only through its official support website and will never ask for a password or Steam Guard code through email, Steam Chat or Discord.
Affected customers should verify the sender and every link before responding to a new message. The same advice is useful beyond this specific breach for anyone whose personal information or login credentials are stored in online services.
Source: 3DJuegos




Leave a Reply