Valve has disclosed a data breach at its European shipping partner, CEVA Logistics, which may have exposed the personal information of customers who ordered Steam hardware in Europe. In an email sent to users, Valve stated that the breach potentially included customer names, addresses, phone numbers, and email addresses.

Timeline of the Incident

The breach at CEVA occurred between July 29th and August 1st, shortly after Valve began taking reservations for its new Steam Machine and Steam Controller. Valve noted that European customer data was "likely compromised" because CEVA stores delivery-related information for up to 90 days following an order.

Warning Against Phishing Scams

As a direct result of the leak, Valve is advising customers to expect fraudulent messages via email, text, or phone. Scammers may quote a user's physical address to appear legitimate while requesting confirmation of delivery or payment of fake customs fees.

“Treat all of them as fake,” Valve warned in its notice to customers.

The company clarified that sensitive information, such as passwords, payment details, and Steam Guard codes, was not impacted, as CEVA does not have access to this data. Valve emphasized that it only manages account issues through its official help portal and will not initiate contact via email, Steam chat, or Discord for such matters.