CEVA Breach Exposes Steam Customer Data in Europe

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CEVA Logistics, Valve's European shipping partner, suffered a data breach between July 29 and August 1 that exposed delivery-related customer data
- Valve notified users that the breach may have included names, addresses, phone numbers, and email addresses of customers who ordered Steam hardware in Europe
- The breach occurred weeks after Valve began taking reservations for its new Steam Machine and Steam Controller
- CEVA stores delivery-related information for up to 90 days after orders, defining the window of potentially exposed data
- Valve warned customers to expect fake messages via email, text, or phone that may quote their address, request small customs or redelivery fees, or ask them to sign in to "verify" an order
- Payment information, passwords, and Steam Guard codes were NOT impacted — Valve emphasized CEVA has no access to those
- Valve stated it only handles account issues through help.steampowered.com and never contacts users via email, Steam chat, or Discord
Why it matters: For European Steam hardware buyers in the affected window, CEVA's 90-day delivery-data retention puts their name, address, phone, and email in the hands of whoever breached CEVA — and Valve's own warning describes precisely the kind of address-quoting phishing that becomes trivial with that data set.
Ask SkimNews



