Particle.news
Download on the App Store

CEVA Logistics Breach Exposes Delivery Data of European Steam Hardware Buyers

The leak raises the risk of targeted phishing that could exploit buyers’ names, addresses and order details.

Overview

  • The intrusion targeted CEVA LogisticsEuropean operations between July 29 and August 1, and Valve says it was notified of the incident on August 7.
  • Attackers exfiltrated delivery-related customer data such as names, shipping addresses, phone numbers, account-linked email addresses and order details while Valve says payment credentials and Steam account passwords were not taken.
  • CEVA has isolated affected systems and engaged external security consultants as Valve prepares notifications to data protection authorities in the affected countries.
  • Valve has sent notices to potentially affected Steam hardware buyers and warns they should treat emails, SMS or calls about deliveries as likely phishing attempts and never share passwords or Steam Guard codes.
  • Other CEVA clients including ING, Ajax and Ace & Tate have reported related data thefts, underscoring wider supply-chain risk and the need for customers of logistics providers to monitor for targeted fraud.