Overview
- Valve says a cyberattack on its European shipper CEVA Logistics occurred between July 29 and August 1 and that the company informed Valve on Friday, August 7, prompting Valve to begin emailing potentially affected customers on Monday, August 10.
- The attackers likely copied delivery-related fields CEVA holds for up to 90 days, including names, street addresses, postal codes, phone numbers, email addresses tied to Steam accounts, and details of the hardware ordered.
- Valve and CEVA say Steam account passwords, Steam Guard codes, and payment information were not stored by CEVA and were not exposed in the breach.
- CEVA has isolated the affected systems, taken them offline, hired external investigators, and reported disruptions at at least eight European warehouses while Valve is pressing CEVA for the full scope and notifying national data‑protection authorities.
- Customers are told to expect targeted email, SMS, or phone scams that may quote their address or ask for fees, to ignore unsolicited links, and to use Valve’s official support site for any questions.