Valve is currently reaching out to an unspecified number of Steam users, specifically those who have purchased Valve hardware, to inform them that its shipping partner in Europe, CEVA Logistics, was subject to a âcyberattackâ in late July.
The source of the news is Steam users themselves, as multiple posts on both ResetEra and Reddit have appeared in the last few hours detailing an email theyâve received from Valve containing details of the CEVA Logistics report.
According to the email, CEVA Logistics was compromised sometime between âJuly 29 and August 1â this year, although Valve notes that they first âlearnedâ of the cyberattack on August 7. However, the Dutch outlet NOS reported on Wednesday that two separate companies, Bol and De Bijenkorf, were informed of the cyberattack on August 1.
Although the email Valve sent out explicitly states that information related to âSteam account or other purchases was not impacted,â it does state that usersâ phone numbers, addresses, email addresses, and names âmay have been compromised.â
Likewise, Valve specifically notes in the email that CEVA Logistics is âthe company that ships Steam hardware to customers in Europe,â so presumably only those who purchased Steam-related hardware in said region are at risk.
The email also states that CEVA Logistics retains usersâ âinformation for up to 90 days after [an] order,â which likely means that anyone in Europe who purchased a Steam product from early August onwards may be at risk. As a result, Valve warned users to âexpect fake messagesâ via email, SMS or phone âthat mention your hardware order and appear to come from Steam, Valve or a delivery company.â
Neither Valve nor CEVA Logistics appears to have released an official statement regarding the cyberattack and is instead directly emailing customers that may be affected by the breach. As a result, itâs currently unconfirmed as to how many Steam customersâ details have been leaked.