Valve said on Monday (10) that it has begun notifying European customers who bought Steam hardware about the possible exposure of their personal data in a cyberattack on CEVA Logistics, the company responsible for deliveries in the region.

In the email sent to those affected, Valve detailed that CEVA suffered the intrusion between July 29 and August 1, and that the company learned of the incident on August 7. Since the carrier keeps delivery data for up to 90 days after the order, Valve is contacting all customers possibly affected within that window.

The exposed information includes names, addresses, postal codes, cities, countries, phone numbers, Steam account email addresses, and the type and price of the hardware purchased. Valve believes buyers of Steam Deck, Steam Machine, and Steam Controller are among the main affected parties. The company stressed that there was no leak of payment data, passwords, Steam Guard codes, or other account data.

Phishing risk

Valve warned of the possibility of phishing attempts by email, SMS, or phone that reference the order and even cite the customer's real address to look legitimate. The manufacturer reiterated that Steam support operates exclusively through the help.steampowered.com website and will never ask for a password or Steam Guard code.

CEVA confirmed the attack in a statement to TechCrunch, saying the intrusion affected part of its contractual logistics operations in Europe and disrupted at least eight of its warehouses on the continent. The carrier, based in France, also said that other banks and retailers using its services were impacted.

Valve said it is asking CEVA for more details about the scope of the attack and how it occurred, and that it has notified data protection authorities in the affected countries. The exact number of customers affected was not disclosed.

More from Radar