Skip to content
Tech News
← Back to articles

Valve Warns Steam Machine Buyers About Scam Messages After Cyberattack

read original more articles
Why This Matters

The cyberattack on Valve's European distribution partner highlights the growing cybersecurity risks in the gaming and tech industry, emphasizing the importance of protecting customer data and being vigilant against scams. For consumers, this incident underscores the need for caution when receiving unsolicited messages related to their purchases, especially in the digital age where personal information is increasingly targeted. It also serves as a reminder for companies to strengthen their cybersecurity measures to safeguard user data and maintain trust.

Key Takeaways

If you’ve been holding out on buying Valve’s ludicrously expensive home console, you may have saved yourself from more than an empty wallet. European customers who ordered a Steam Machine or Steam Controller may be the victims of a personal information data breach after one of Valve’s hardware distribution partners was hit by a cyberattack.

CEVA Logistics, the company that helps organize Valve’s European supply chain, informed its partner of the data breach on Aug. 7. A Valve spokesperson told CNET that the company spent the weekend assembling a list of at-risk customers, notifying them about the attack via email on Monday morning.

“Though CEVA is still investigating the attack, we wanted to at least send out messaging to all customers we can assume were affected based on what we currently know,” the spokesperson said.

What Valve currently knows is that the personal information revealed by the cyberattack is likely all delivery-related. CEVA told Valve that the breach revealed customers’ names, countries, street addresses, phone numbers and email addresses. According to Valve, “payment information, passwords and Steam Guard codes” are all safe, since CEVA doesn’t have access to this data.

Because phone numbers and email addresses linked to Steam accounts are openly circulating, Valve warned against phishing attacks that may be looking for additional personal information in the coming days.

Read more: Best Data Removal Services of 2026: Reduce Your Online Presence

“Expect fake messages – email, SMS or phone – that mention your hardware order and appear to come from Steam, Valve or a delivery company,” Valve wrote in its email to affected customers. “They may quote your address back to you to prove they’re genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee or sign in somewhere to ‘verify’ your order. Treat all of them as fake.”

Valve reminded customers that Steam’s support team only handles issues on the official help page and never sends messages over Steam chat or through third-party services. Company employees will also never ask for a customer’s password or Steam Guard codes.

The finer details of the attack currently remain unclear, as there’s no official information available on how many customers were affected, how much data was stolen or how the cyberattack infiltrated CEVA Logistics’ systems. In its statement, Valve said it is “pressing CEVA for the full scope” of the breach.

Alongside CEVA’s internal investigation, authorities in the Netherlands are looking into the attack. A spokesperson for the Dutch data protection authority told TechCrunch that the agency has received data breach reports from at least 10 companies in relation to the hack.

... continue reading