Valve is currently reaching out to an unspecified number of Steam users, specifically those who have purchased Valve hardware, to inform them that its shipping partner in Europe, CEVA Logistics, was subject to a “cyberattack” in late July.

The source of this news is Steam users themselves, as multiple posts on both ResetEra and Reddit have appeared in the last few hours detailing an email they’ve received from Valve containing details of the CEVA Logistics report.

According to the email, CEVA Logistics was compromised sometime between “July 29 and August 1” of this year, although Valve notes that they first “learned” of the cyberattack on August 7. However, the Dutch outlet NOS reported on Wednesday that two separate companies, Bol and De Bijenkorf, were informed of the cyberattack on August 1.

Although the email Valve sent out explicitly states that information related to users’ “Steam account[s] or other purchases was not impacted,” it does state that their phone numbers, addresses, email addresses, and names “may have been compromised.”

Likewise, Valve specifically notes in the email that CEVA Logistics is “the company that ships Steam hardware to customers in Europe,” so presumably only those who purchased Steam-related hardware in said region are at risk.

The email also states that CEVA Logistics retains users’ “information for up to 90 days after [an] order,” which likely means that anyone in Europe who purchased a Steam product from early April onwards may be at risk. As a result, Valve warned users to “expect fake messages” via email, SMS or phone “that mention your hardware order and appear to come from Steam, Valve or a delivery company.”

Neither Valve nor CEVA Logistics appears to have released an official statement regarding the cyberattack and is instead directly emailing customers that may be affected by the breach. As a result, it’s currently unconfirmed as to how many Steam customers’ details have been leaked.

Share.
Exit mobile version