The gaming giant has warned that fraudulent emails could follow the data breach.
All Steam hardware owners in Europe should be on the lookout for scam messages in the near future after Valve said the personal data of some of its customers was exposed in a cyberattack. In an email sent to affected customers, Valve said that a company that ships its Steam hardware products to its European users, called CEVA Logistics, suffered a data breach between July 29 and August 1. Valve said it learned on August 7 that the cyberattack had led to some personal information on Steam customers being “likely compromised.”
According to Valve, the stolen information includes names, addresses, phone numbers, emails and order details. However, the company clarified that CEVA does not have access to customers’ payment information, passwords, Steam Guard codes, or any other similar sensitive information. Valve added that affected users do not need to change their Steam passwords or account details.
Looking ahead, Valve warned in the email that some customers can “expect fake messages – email, text or phone – mentioning your hardware order and appearing to come from Steam, Valve or a delivery company.” Valve said these fake messages could use sensitive information like addresses or order details to convince you to pay a small customs or redelivery fee, or even log into something to verify the order. Valve said it was “putting pressure on CEVA to find out the full scope of what was taken and how”, adding that it was “in the process of informing the data protection authorities of the affected countries”.
