Updated
Updated · The Verge · Aug 10
CEVA Breach Exposes 4 Types of Steam Customer Data in Europe
Updated
Updated · The Verge · Aug 10

CEVA Breach Exposes 4 Types of Steam Customer Data in Europe

3 articles · Updated · The Verge · Aug 10

Summary

  • Valve told European Steam hardware buyers that CEVA Logistics suffered a breach that likely compromised names, addresses, phone numbers and email addresses tied to deliveries.
  • July 29 to Aug. 1 is the window Valve gave for the incident, which came weeks after it opened reservations for the new Steam Machine and Steam Controller.
  • Valve warned affected customers to expect phishing by email, text or phone, including messages that cite their address and ask for delivery confirmation, small fees or sign-ins.
  • CEVA stores delivery-related information for up to 90 days, but Valve said the shipper does not have access to payment details, passwords, Steam Guard codes or other Steam account data.

Insights

How did a shipping partner's data retention policy turn European Steam gamers into prime targets for identity thieves?
Will the cyberattack on CEVA Logistics force major tech companies to completely overhaul their third-party shipping security protocols?