Valve has announced that the shipping and delivery data of certain users who ordered the Steam Machine and Steam Controller in Europe was leaked as a result of a cyberattack targeting its third-party logistics partner, CEVA Logistics. During the data breach, which was detected on August 7, users' financial information remained secure, but personal shipping details such as names, addresses, emails, and phone numbers fell into unauthorized hands.
Scope of the Breach and Affected Data
CEVA Logistics, the target of the attack, was storing specific delivery data received from Valve to carry out physical shipments. According to initial investigations, the data accessed by the cyberattackers includes:
- Customer's full name
- Complete delivery address
- Email address
- Phone number
The launch process of the Steam Machine and Steam Controller—which had previously made headlines due to rapidly depleted stocks in the Japanese market and various delays—is now facing a new crisis with this security breach.
Are Financial Information and Steam Accounts Safe?
According to an official statement by Valve, financial data that was not held on the logistics company's systems is completely secure. CEVA Logistics does not have access to credit card numbers, bank details, or account security keys.
Similarly, users' primary Steam accounts, passwords, Steam Guard codes, and digital game libraries were unaffected by the leak. However, users are warned to remain vigilant, as the leaked email addresses and phone numbers could potentially be used for future phishing or scam attempts.
Industry Implications
This incident once again highlights the massive cybersecurity risks that digital gaming and hardware giants face through their supply chain and logistics partners. No matter how secure companies' own infrastructures are, security vulnerabilities of third-party business partners can directly impact end users. This incident has reignited debates on the necessity for technology companies—especially those engaged in e-commerce and hardware shipping—to more strictly audit the data security standards of their business partners.
Frequently Asked Questions
Could the primary Steam accounts of users whose shipping data was leaked have been compromised?
No. The leak only covers contact and address information transferred to the logistics company for physical cargo delivery; passwords, Steam Guard codes, and account access information were unaffected by this incident.
How can users individually protect themselves against data leaks from third-party logistics firms?
Users should be cautious against suspicious SMS messages and emails containing their personal information originating from shipping companies or e-commerce sites, and should verify such communications directly through official channels without clicking on links.
*This news is based on data published by Webtekno — Artificial Intelligence.
💬 Comments
No comments yet. Be the first!
You must be logged in to comment.
🔑 Log In