As if there hadn’t already been enough commotion surrounding the release of the Steam Machine, buyers in Europe are now also facing a data breach. The local distributor of the hardware is affected.
This is extremely unpleasant news that Valve has had to convey to customers across Europe in recent days. According to an email from the company shared by user “nelsonsflagship” on Reddit, personal information belonging to a large number of customers has been stolen. This includes names, addresses, phone numbers, and email addresses linked to Steam.
However, it was not Valve itself that was hacked, but rather the logistics company through which its hardware is distributed in Europe: CEVA Logistics. According to Valve, this company receives “specific delivery-related information from Steam in order to ship the physical hardware to customers in Europe.” It is precisely this information that was stolen.
Purchases Since Early May Affected
The cyberattack reportedly took place “between July 29 and August 1.” This means that potentially all European customers who have ordered hardware directly from Steam since the release of the Steam Controller in early May could be affected. CEVA stores this information for up to 90 days after an order is placed—at least according to Valve, which notified all affected customers via email.
However, more detailed information regarding the Steam accounts or even the payment methods of those affected was not stolen. “CEVA does not have access to payment information, passwords, Steam Guard codes, or other information,” the company stated.
Nevertheless, the data breach could have unpleasant consequences for buyers. For example, Valve warned of fraudulent phishing emails or text messages referring to the respective order. This is yet another annoyance surrounding the Steam Machine and related products, after a release delay and the pricing policy had already generated little enthusiasm among prospective buyers.

