Urgent.News

What's breaking now, across thousands of outlets.

Tech

"Expect fake messages": A load of Steam user personal info has been stolen thanks to a cyberattack on one of Valve's partners, claims report

If you live in Europe and have bought hardware from Steam in the past three months, then watch out, your personal information might have been stolen thanks to a cyberattack on one of Valve's shipping partners. Read more

"Expect fake messages": A load of Steam user personal info has been stolen thanks to a cyberattack on one of Valve's partners, claims report

A cyberattack has compromised personal information of Steam users in Europe, according to a report from Valve. The breach occurred at CEVA Logistics, a partner responsible for shipping Steam hardware to customers in Europe between July 29, 2026, and August 1, 2026. CEVA, which retains delivery information for up to 90 days, obtained names, phone numbers, email addresses, and postal addresses from Valve when shipping hardware to European customers.

Valve has alerted users about the potential data breach and urged them to be cautious of fake messages that may appear to be from Steam, Valve, or delivery companies. These messages may request personal information or financial details, but Valve has stated that credit card information, passwords, Steam Guard codes, and other sensitive data were not compromised. Users should disregard any suspicious communications and avoid clicking on links or providing any personal information.

Valve is working with CEVA to determine the extent of the data breach and is notifying relevant data protection authorities. While there is a possibility that the email could be a sophisticated attempt to deceive users, Valve advises users to follow standard safety precautions, such as not clicking on links, not sharing passwords or Steam Guard codes, and typing in Steam store addresses directly.

The report emphasizes the importance of vigilance in protecting personal information, especially in light of recent cyber threats.

Written by urgent.news from Rock Paper Shotgun's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at rockpapershotgun.com →

More in Tech

77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data

Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to…

  • 77 counterfeit Open VSX extensions collected developer data.
  • Extensions targeted credentials, source code, and CI/CD systems.
  • All 77 extensions removed by August 3, but persistence risk remains.

More from Monday 10 August →