CEVA Logistics breach exposes Steam customer data in Europe

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CEVA Logistics suffered a data breach between July 29 and August 1 that likely exposed the names, addresses, phone numbers, and email addresses of European customers who ordered Steam hardware.
- Valve warned affected users to "expect fake messages" via email, text, or phone claiming to come from Steam, Valve, or a delivery company—potentially quoting the user's address back to them and asking for customs or redelivery fees.
- The breach landed weeks after Valve began taking reservations for its new Steam Machine and Steam Controller; CEVA stores delivery-related information for up to 90 days after orders.
- Valve clarified that payment information, passwords, and Steam Guard codes were NOT impacted, stating CEVA "does not have access" to that data.
- Valve said it only handles account issues through help.steampowered.com and will not contact users via email, Steam chat, or Discord.
Why it matters: European Steam hardware buyers now face a targeted phishing risk: Valve says scammers may quote real leaked addresses to appear legitimate, and the breach timing coincides with the Steam Machine and Steam Controller reservation window. With payment and account credentials confirmed safe, the threat is social engineering during a high-traffic product launch, not account takeover.
Ask SkimNews



