Skip to content
News

Valve Warns Steam Machine Buyers of Scam Messages

Valve Warns Steam Machine Buyers of Scam Messages - Steam Machine data breach
Valve warns European Steam Machine buyers of scam messages after a cyberattack on distributor CEVA Logistics exposed customer delivery details.

Valve has warned European buyers of the Steam Machine and Steam Controller that their personal information may have been exposed after one of the company’s hardware distribution partners suffered a cyberattack. Customers who placed orders across Europe could be affected by the data breach.

CEVA Logistics, the firm that helps coordinate Valve’s European supply chain, notified its partner of the breach on 7 August. A Valve spokesperson said the company spent the weekend compiling a list of at-risk customers, sending notification emails on Monday morning based on what it currently knows about the attack.

What Information Was Exposed

According to Valve, the compromised data appears to be delivery-related. CEVA reported that the breach revealed customers’ names, countries, street addresses, phone numbers and email addresses. Payment information, passwords and Steam Guard codes are said to be safe, as CEVA does not have access to that data. Affected customers do not need to change their Steam passwords or account settings.

Because phone numbers and email addresses linked to Steam accounts are circulating openly, Valve cautioned users about potential phishing attempts in the days ahead. The company told customers to expect fake messages via email, SMS or phone that reference their hardware order and appear to come from Steam, Valve or a delivery company. Such messages may quote a customer’s address to seem legitimate, or ask them to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to verify an order. Valve advised treating all of them as fake.

Ongoing Investigation and Warehouse Disruption

Valve reminded customers that Steam’s support team only handles issues through the official help page and never sends messages over Steam chat or third-party services. Company employees will never ask for a password or Steam Guard codes.

The full details of the attack remain unclear. There is no official information on how many customers were affected, how much data was stolen or how the attackers infiltrated CEVA Logistics’ systems. Valve said it is pressing CEVA for the full scope of the breach.

Authorities in the Netherlands are also examining the attack. The Dutch data protection authority said it has received data breach reports from at least 10 companies in connection with the incident. Operations at eight of CEVA’s warehouses have reportedly been affected, potentially causing delays or cancellations to customer orders in the coming days.

Source
Image: cnet.com

The UK tech briefing

Smartphones, AI, computing and deals — the essential stories without the noise.

Mailing provider can be connected when your UK list is ready.

Shop on Amazon UK — Discover deals Shop on Amazon UK — Discover deals