Valve Corporation has begun notifying European customers who purchased Steam hardware that their personal information may have been exposed following a significant cyber attack on one of its distribution partners. The gaming giant, known for its popular Steam platform and hardware products like the Steam Deck, confirmed that a security breach occurred at a third-party logistics company responsible for shipping products across Europe, potentially affecting thousands of customers who made purchases in recent years.
Multiple users across various online platforms, including Reddit, reported receiving official emails from Valve on the same day, alerting them to the security incident. The communications detailed that CEVA Logistics, the distribution company contracted to handle the shipping of Steam hardware products throughout the European market, experienced a cyber attack that occurred between July 29 and August 1 of this year. The breach reportedly lasted approximately four days before being detected and contained, raising concerns about the extent of data that may have been accessed during this window.
Details of the Security Breach and Affected Products
The security incident specifically affected customers who purchased Valve’s hardware lineup, which includes the highly popular Steam Deck handheld gaming console, the now-discontinued Steam Machine gaming computers, and the Steam Controller. CEVA Logistics, a global supply chain management company headquartered in Switzerland, handles warehousing and distribution for numerous major technology companies worldwide. The company operates in over 170 countries and manages millions of shipments annually, making it an attractive target for cybercriminals seeking valuable customer data.
According to the notifications sent to affected users, the compromised data likely includes personal information typically associated with shipping and delivery services. This may encompass names, physical addresses, phone numbers, and email addresses that customers provided during the checkout process. While Valve has not explicitly confirmed whether payment information was accessed, the company’s standard practice of processing payments directly through its platform rather than through logistics partners may provide some protection for financial data.
The Growing Threat of Supply Chain Attacks
This incident highlights the increasing vulnerability of companies to cyber attacks targeting their supply chain partners and third-party service providers. In recent years, supply chain attacks have become a preferred method for cybercriminals, as they allow hackers to potentially access data from multiple organizations through a single point of entry. Major incidents like the SolarWinds breach in 2020 demonstrated how devastating these attacks can be, affecting thousands of organizations including government agencies and Fortune 500 companies. For gaming companies, which often rely on complex networks of manufacturers, distributors, and logistics providers, protecting the entire supply chain has become a critical security challenge.
CEVA Logistics has not yet issued a public statement regarding the specific nature of the attack or the total number of affected individuals. Cyber attacks on logistics companies have been increasing in frequency, with the transportation and shipping sector experiencing a 186% increase in ransomware attacks over the past two years, according to industry security reports. These companies are particularly vulnerable due to the vast amounts of customer data they handle and the critical nature of their operations, which can make them more likely to pay ransoms to restore services quickly.
Valve’s Response and Customer Recommendations
Valve’s decision to promptly notify affected customers demonstrates compliance with the European Union’s General Data Protection Regulation, which requires companies to inform individuals about data breaches within 72 hours of becoming aware of incidents that may pose risks to their rights and freedoms. The GDPR also mandates that companies report such breaches to relevant supervisory authorities, potentially subjecting both Valve and CEVA Logistics to regulatory scrutiny regarding their data protection practices.
Customers who received the notification are being advised to remain vigilant against potential phishing attempts, suspicious emails, and unsolicited communications that may attempt to exploit the stolen information. Security experts recommend that affected individuals monitor their accounts for unusual activity, consider updating passwords associated with their Steam accounts, and be particularly cautious of any communications claiming to be from Valve or related shipping services. The incident serves as a reminder that even when companies maintain strong internal security practices, vulnerabilities in partner organizations can still put customer data at risk.
Expert Opinion: This breach underscores a critical vulnerability in modern e-commerce ecosystems where customer data flows through multiple third-party handlers beyond the primary retailer’s control. Companies like Valve must increasingly implement rigorous vendor security assessments and contractual data protection requirements for all supply chain partners. Moving forward, we can expect regulatory bodies to place greater scrutiny on how companies vet and monitor their logistics partners’ cybersecurity practices, potentially leading to new compliance frameworks specifically addressing third-party data handling in retail operations.
