Valve partner leaks names addresses of Steam buyers
When you order cutting-edge gaming gear, you expect seamless delivery and rock-solid security. But lately, a recent incident involving Valve’s European shipping partner has introduced some unexpected twists regarding customer data privacy.
An email circulated this morning detailed a cyberattack targeting CEVA Logistics, Valve’s shipping partner in Europe, on August 7. This event prompted concerns among customers who had ordered products like the Steam Machine gaming PC or modern Steam Controllers within the continent.
The immediate reaction was understandable: what exactly was at risk?
Valve quickly clarified that while the attack affected their logistics partner, it did not compromise the core security of customer accounts. Specifically, Valve confirmed that the breach does not affect your payment information, passwords, Steam Guard codes, or any other sensitive account details.
So, if you are worried about your Steam account security, take a deep breath. There is currently no need to change your password or alter any settings. Your account remains secure.
However, the situation does bring a very real warning regarding identity theft and phishing attempts. The data potentially exposed in this incident included personal details such as your name, street address, postal code, city, country, phone number, email address (the one linked to your Steam account), and the type and price of the ordered product.
This is where vigilance becomes essential. Bad actors are known to exploit data breaches to attempt various identity frauds. Therefore, customers should expect fake messages—emails, SMS, or phone calls—that appear to come from Steam, Valve, or a delivery company, asking for money or further personal information.
It is crucial to remember that Valve only handles account issues through its dedicated support site, and they emphasize that genuine support never comes via email, Steam Chat, or Discord. Anyone claiming to be Steam Support through these channels is not legitimate.
If you receive a suspicious message from a delivery service demanding action, treat it as fake. Valve explicitly advises customers to “Treat all of them as fake” when responding to such requests.
While the breach focused on European operations, it is important to note that customers located outside CEVA Logistics’ operating area in Europe—including those in the United States—should not be affected by this specific incident. Nevertheless, this event serves as a potent reminder about customer privacy and data security in the digital age.
Ultimately, maintaining strong cybersecurity habits is your best defense. Keep using unique, strong passwords for every platform and remain highly scrutinizing of every message that demands personal details.