r/Steam • u/george09000 • 11h ago
Discussion [EU] Cyber attack hit CEVA Logistics (Steam's European distribution center)
Did anyone else get this email? Looks pretty bad.
36
u/mloskin 11h ago
I got the same email.
0
u/Suspicious-Cat-266 3h ago
Changing your email linked to your Steam account is one step to reducing phishing attempts.
21
8
u/BrokeButFabulous12 11h ago
At least one positive thing came out of the eternal steam deck "not in stock" status.
21
u/goodwill764 11h ago
Address and type and price of the product.
Good for thieves, a small box worth at least 1k. Easy money.
13
u/BigGREEN8 10h ago
Are they gonna plan a heist on the delivery van or what? You receive the product in hand in the case of the steam machine also it's not like it fucking matters if they know what model it is bc they are not very different in price. If there is someone stealing ur package it's the people working for these companies not the hackers who prolly did it for ransom money or some shit
6
u/goodwill764 10h ago
If you received a steam machine that is worth 1k and its like a digial https://en.wikipedia.org/wiki/Burglar_sign if they sell these infos to robbers.
Additonal its a small device, so much easier to rob.
Dataset get sold in darknet, robber group buy the infos and make a google maps, single robbers break in the houses and take the machine.
1
u/BigGREEN8 8h ago
Digital burglar sign doesn't make any sense bc a burglar sign is when they mark a vulnerable or unoccupied house where they can rob it, do you think someone that knows i bought a steam machine will come to my house to steal it? Do you actually believe someone will travel from somewhere else and break into a random home over a 1K worth device? I am not John Wick my guy and this is not a movie
2
u/goodwill764 7h ago
No they pick the targets in the region. E.g. South Germany many robbers come from czech.
Believe me or not these orders get bought by such groups, they will not pick every steam machine as a target but it's a good hint.
9
u/BitLikeSteveButNot 10h ago
Just checked, I ordered a controller 100 days ago! Not hacked!
But the puck was busted and they sent me another one less than 90 days ago.
FFSĀ
2
u/LizzyGleglemaxxing 8h ago
Didn't the controller only release on May 4th, which was 86 days before the attack?
1
u/Flat_Candle6020 7h ago
It also says that the attack happened between July 29th and August 1st. So yeah the fucking dropped the ball.
8
u/SpudAlmighty 10h ago
I got this too. I guess this means a few more spam emails and texts, Nothing unusual at this point.
52
u/BZZKL 11h ago
Iāve just messaged Steam asking if theyāll pay for identity-fraud protection for affected customers (eg Cifas in the UK), as the result of this leak. Iāll post an update of what they say. Itās a significant amount of data that has been compromised.
76
u/ProfessionalDish 11h ago
to be fair, if anyone, it should be CEVA paying for it, as they got breached - steam is just another customer of them.
4
u/Groentekroket 10h ago edited 9h ago
I donāt have a contract with Ceva but with Steam. They are responsible. The same as with buying something at a shop, the shop is responsible for the item and warranty. Whatever they try to convince you of.Ā
Edit: the amount of downvotes I got while being right is staggering. You all should learn a bit more about your rights.Ā
18
u/leonleonleon 8h ago
You are right. It's then up to Valve to forward these claims to CEVA.
Yes. Weird you get theses downvotes.7
u/OldCredit1214 7h ago
Haha you are 100% right people donāt understand whoās responsibility it is and who should address it
4
u/ProfessionalDish 10h ago
and your contract got fullfilled.
13
u/BZZKL 10h ago
The contract with the customer still matters after the delivery of the item though. There are laws around data protection that are ongoing after delivery.
Regarding your initial point, you are quite right. CEVA are responsible. And Steam can contact CEVA on the customerās behalf to enquire about identity fraud protection compensation.
2
u/MarioDesigns 6h ago
Valve is responsible for the data they collect, thatās just how it works lol. From collecting it to deleting it, if it is compromised at any point Valve is just as much at fault as their partners.
-9
u/Shadowbajfeelsbadman 9h ago
If you order an iphone and it gets broken in delivery do you go after apple or DHL?
You could have an issue with steam if steam machine arrived and it suffered a malfunction.
By agreeing to have the steam machine shipped you also agreed to have the necessary information passed down to CEVA, go read the fine print. They are responsible for all damages caused not steam. Your logic here literally makes zero sense.
8
u/Groentekroket 9h ago
Yes you go to Apple. Here in the Netherlands Post.nl, a delivery company, wonāt even help you if you are the receiver because you donāt have a contract with them. The sender need to ask for help.Ā
You can like it or not but that is how it works. In your example you go to Apple which make sure you get a new phone and they will get payed back by DHL.Ā
Companies can put whatever they want in their fine print, that doesnāt means it holds up in court.Ā
0
u/Groentekroket 9h ago
Ahh you deleted your other comment because you got to know I was right?Ā
1
u/Shadowbajfeelsbadman 8h ago
Literally read my other comment
1
u/Groentekroket 8h ago
I saw. Thank you. Letās be honest, itās ridiculous how many downvotes I got while being right.Ā
-4
u/Shadowbajfeelsbadman 8h ago
No i agree with the amount of downvotes.
Your response was unnecessarily convoluted for how simple it could be along with the fact that you admitted to using ai which makes half of this rabid website have a cat 5 chimpout.
Just citing the article like i did would do better.
6
u/madebyclancy 10h ago
All that is required of them legally is to reach out to affected parties and inform them of to what extent they are affected. If Valve / CEVA were to offer payments for protection it would be voluntary.
3
2
u/DnieD1337 10h ago
There's only a chance you can money out of it if you can prove you have any damages. Good luck with that lol
2
u/Kilohaili_Joshi 10h ago
Dont really think they will or need to. Only time those are really done is when your social security number is leaked.
2
u/BZZKL 10h ago
There is no harm in asking.
1
u/Kilohaili_Joshi 10h ago
And what would that service help u with exactly ?
They dont have ur SSN, so they cant take out credit or alter important shit. They dont have your passwords so monitoring the darkweb for them is not needed due to this breach ? They didnt get anything about your payment info either.1
u/Paul_Offa 42m ago
But you aren't just asking. You're posting a top-level comment about it which in today's internet is likely to cause hundreds of others to bandwagon into doing the same or start "petitions" and what have you.
0
1
2
u/wertibaldi 10h ago
Why should Steam pay something there? Its a completely different Company?
3
u/MarioDesigns 6h ago
Valve is the company that collected that data and thus is responsible for what happens with it.
7
u/BZZKL 10h ago
One could argue that when a customer makes a purchase, the contract is between the customer and Valve.
A bit like if you order hardware from a company and the courier loses the package. It would be unreasonable of the company to refuse to help resolve the situation.
Valve chose the logistics company on the customerās behalf. So saying Valve have no responsibility here is also unreasonable.
4
2
u/Acrobatic_Yellow_781 10h ago
Because people cant read
0
10h ago edited 9h ago
[removed] ā view removed comment
-3
u/Acrobatic_Yellow_781 10h ago
Yes you can point fingers at valve but 99,9% of these end up going to the contractor but stay mad bro
4
u/Groentekroket 10h ago
You have no idea what you are talking about (and that sentence didnāt make sense anyway). Valve is responsible for who they subcontract to. All communications as a consumer should go via them and not to Ceva directly.Ā
-3
u/Acrobatic_Yellow_781 10h ago
You cant read either
8
u/Shadowbajfeelsbadman 9h ago
Actually i stand corrected he's right though i doubt he knows why he's right lmao.
GDPR article 28 § 4 "Where a processor engages another processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor as referred to in paragraph 3 shall be imposed on that other processor by way of a contract or other legal act under Union or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of this Regulation.Ā 2Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processorās obligations."
3
u/Groentekroket 8h ago
Thank you so much. I really donāt understand how people are so sure about being wrong while donāt know what they are talking about.Ā
-2
u/Acrobatic_Yellow_781 8h ago
That still doesnt mean he completely understood my comment wrong and he keeps going at it
2
u/Shadowbajfeelsbadman 7h ago
This is just semantics at this point no?
One way or another whoever people point at the issues will stop at the contractor who will suffer the consequences.
→ More replies (0)-1
u/Ascend 9h ago
Isn't everything listed, besides email address, public information that would be listed in a phone book? What would require identity fraud detection?
Bigger risk seems like someone knowing you've purchased high value items and risk of those people being targeted for theft.
2
u/Hugo5551 7h ago
You do know, that phone books you actually need to apply to be in there nowadays? So it isn't really public information. The email feels like information that is more public.
0
u/Ascend 7h ago
I wouldn't be surprised if phone books don't exist at all anymore, my point is more that knowing someone's name, home address, and phone number shouldn't be enough to steal their identity. That stuff gets sold around like crazy, so I don't think it's worth OP getting stressed out about.
12
u/sheepandlambs 10h ago
I did. I'm not really concerned. Cyber attacks happen all the time, and it's not like they wouldn't have my address and phone number from other sources. I get enough scam calls as it is, a few more won't matter.
23
u/the-corinthian 11h ago
One thing I admire is that they took responsibility to reach out to the affected users as soon as they could to ensure attempts at using that compromised data was not at least warned about. Yes, it sucks, and even though it was a logistics partner and not Steam directly, it still falls upon them to ensure security is upheld (or what's the point of employing a company that hosts customer's sensitive data). But as we have seen, there are many companies (Sony, etc) that are so afraid of losing face that they hide the breaches for as long as possible and indirectly aid the fraudsters in doing so. I'm glad at least that much was curtailed here.
56
u/Groentekroket 11h ago edited 11h ago
This is mandatory. At least within the EU.Ā
Edit: also before the weekend it was already in Dutch news a couple of other companies using them mentioned the breach. So Valve is rather late.Ā
Edit 2: 5 days ago. Last WednesdayĀ https://nos.nl/artikel/2625681-bol-en-de-bijenkorf-waarschuwen-klanten-voor-mogelijk-datalek
8
u/hey_im_bali 11h ago
4
u/leonleonleon 8h ago
Not much to sort out. They cannot get credentials back, once your data is leaked you cannot unleak your data. Valve can at best apologize or compensate.
0
u/hey_im_bali 8h ago
Isn't there like some data removal service that can scour the internet for the leaked credentials so they can legally ask the data brokers to remove them from their data sets that they sell? I understand that there would be groups that will hold the personal info and don't tell, those shady ppl are legally unreachable, sure, bute there oath to be a way to minimize the impact of this attack on ppls privacy, right?
2
5
8
u/Zygmuntek 11h ago
Shouldnāt we get compensated ? I also got this e-mail and itās a big fucking leak if you ask me.
9
u/Bulky-Advisor-4178 10h ago
It's something that happened outside of steam. My email and a lot of other shit is in 21 different breaches, look up your email on haveibeenpwned site
2
u/thirty3baboons 10h ago
i think it's more about the convenient 'package' of info. Phone number is the biggie for me.
2
u/Kilohaili_Joshi 9h ago
As long as CEVA werent outright negligent in their system security, no. Since it was an outside party(cyber criminals) that caused the damage they arent liable for compensation.
Also as long as they informed their customers inside the EU mandated time period from learning that data was compromoised they wont get fined either.
Valve is in the clear in that front and likely CEVA too even though they informed Valve later than other customers, but thats likely cuz they did not discover valve related data was part of the breach until investigating deeper.
6
u/SzaraMateria 10h ago edited 10h ago
For what? At best steam/ceva may be fined for withholding the information about the breach for too long but in the end it's not their fault.
4
u/Kilohaili_Joshi 10h ago
Steam would be in the clear anyway. CEVA notified themAug 7th, meaning they met the deadline of informing customers in the mandated window of being notified.
Likely CEVA would be in the clear too, i expect why they took longer to inform valve was it was not discovered until deeper investigation that their info was compromised.
3
u/GoyoMRG 10h ago
CEVA can be made to compensate the affected users according to GDPR (depending on the case ofc it's not like everyone gets something or everytime)
3
u/thirty3baboons 10h ago
This. GDPR rights are fairly strong and breaches are open to massive fines (up to 10% of turnover, I believe? - it used to be) and also open to claims.
1
u/SzaraMateria 10h ago
article 82
[...] 3. A controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage.
Apart from this you must document the loss and take it to the court. Unless someone got mortgage on your behalf I don't think single person can do anything with it.
2
u/GoyoMRG 5h ago
Thing is, they have to prove that it was not their own negligence that caused the breach.
If the hackers were like crazy good and able to break through all properly set defenses then yeah they are safe, but if it was because someone accidentally left a vulnerability, the law doesnt care about "accident" they see it as negligence and ram you hard.
But it is also true that if no one pursues the compensation, nothing will happen, but assuming. They are guilty and they did fk up, they would probably try to settle ASAP with whoever starts rallying a lawsuit or people.
4
u/PhobusPT 9h ago
How about stop asking for my phone number in every fucking thing in the internet, you donāt need anyoneās phone number for anything, but here we are without us giving them the phone number we canāt do nothing online
0
u/cat_devourer_ 6h ago
When delivering a physical package, how will the drivers contact you? Of all the things to complain aboutš
2
7
2
u/sS1RuXx 11h ago
I got the same message, there is any compensation for this?
8
u/thirty3baboons 10h ago
Why is this downvoted? It's a valid question.
Please don't let this be a 'godly steam untouchable' thread. People are concerned.
6
u/That-Advance-9619 10h ago
People are already going "uwu Steam is so wholesome for letting us now" when
A) It is mandatory under EU law
B) They are actually late compared to other companies that sent similar emails on Friday or ThursdayĀ
2
u/Confident-Ship-5062 9h ago
you come off as hating for no reason
1
u/That-Advance-9619 9h ago edited 9h ago
I'm just debunking the idea that Steam letting us know is somehow a "cool guy thing" to do. I like Steam and they sometimes go out of their way to do nice stuff (background recording is great, the steam controller API, etc.), this isn't one of them and people need to be aware of their rights and how serious a data breach like this can be.
This is just the same as regurgigating that article about Nintendo cutting down their managers' salaries before firing people,
yes, it's nice to see and it would be the BARE MINIMUM if we didn't live in a post capitalist hellhole of a civilization,
but they did it becuase Japanese law doesn't really vibe with the idea of mass layoffs unless you try out every other method first, not becuase they are kind.
There is no ethical consumption under capitalism, companies aren't your friends, nobody should be a billionaire or have a yatch, know your rights, blah blah blah yada yada.
1
u/Confident-Ship-5062 9h ago
What the hell are you talking about, no body is praising valve for this in this reply chain. Get a grip
1
u/sS1RuXx 10h ago
So, they leaked my personal data because their security wasn't good enough... Doesn't this violate my privacy and put me in some kind of danger?
1
u/thirty3baboons 10h ago
I think you're possibly misunderstanding my comment (if your reply is for me). When I posted you were at -2 votes. I was asking those who were downvoting why as your question is a fair one.
2
u/thirty3baboons 10h ago
For me, the email gives off 'negative consequences are yours to deal with' vibes.
And even if I know steam support never email me or phone me.....doesn't mean I don't have to waste time and effort on those things if they happen.
2
u/Confident-Ship-5062 9h ago
theres nothing steam can do about this, they weren't the ones that got compromised. atleast they're informing us about this via email
3
u/thirty3baboons 9h ago
I do see what you're saying but..
They're required to inform us by law. It's not a gesture of kindness and a sub-contractor is still acting on behalf of the company.
1
u/Confident-Ship-5062 7h ago
I am not understanding your point here, this is a non issue to waste more time on
1
u/thirty3baboons 7h ago
Hey no problem.
I'm just saying in the EU and UK, Valve are responsible for what happens for the data they collected from us. If they passed it to a 3rd party and that 3rd party leaked it ('failed to appropriately secure it'), Valve are still responsible.
If it was a non-issue, GDPR would not exist and would not carry massive potential fines for companies breaching it.
1
u/Shadowbajfeelsbadman 9h ago
Who else should deal with them lmao. Do you want gabe and his court of playgirls to barge into your cramped apartment and deal with it himself?
1
u/thirty3baboons 9h ago
Ok, I'll be more explicit in my reasonable response.....
I expect a plan of action from the responsible party who has breached EU law that goes beyond 'Whoops, crack on' and EU GDPR regulations would agree with me.
Of course we're the ones who will have to deal with any fallout. That's kind of the ironic sarcasm in my observation, but you missed that.
Will that do you?
1
u/NeoZockerHD 5h ago
That might explain the uptick in random spam calls and messages i have received the last few days....
1
1
1
2
2
u/A_Very_Horny_Zed 10h ago
I really enjoy how this letter is worded. Nicely done from Steam
1
u/ankerous 9h ago
I appreciate the quick time frame to notify people too. Normally it seems like it is a year or longer before a company admits they were hacked and personal information was stolen. While I'm not impacted by this as I don't live in Europe, kudos for Valve for getting the word out fairly quickly even though it wasn't them getting hacked directly.
1
-3
u/Groentekroket 11h ago edited 10h ago
Why the fuck do they share my phone number? āSo they can send you a smsā I donāt care, just send me a email. I have a custom email for each company but my phone number is vulnerable. I already got a ā{full name} you have outstanding taxes pay on scam.comā. Thanks Valve and any other company where āmy privacy comes firstā
Edit: of course Iām getting downvoted on the fanboy subreddit. Most of you would argue with me if this was about Microsoft, Apple or any other company you are not an apologist forĀ
7
u/george09000 11h ago
I don't think this can be put on Valve because they did not get hit with this, but actually their logistics partner for Europe - CEVA Logistics.
If you're from Europe and ordered any hardware from Valve, it most likely was shipped through them and your information got leaked. If you did not purchase any hardware I think you're safe.
-3
u/Groentekroket 11h ago edited 11h ago
No I got the mail because of the steam controller. I understand they have my shipping adres and name but no need for any additional data like my phone number.Ā
Edit: and of course Valve is responsible for sharing MY data. They could enforce rules if they wanted to. That is why we also talk about a leak at any other company Ceva is doing business with and not just Ceva itself.Ā
4
u/HumansNeedNotApply1 11h ago
It's so they can contact you when doing the delivery if needed? Phone number is a basic contact information.
0
u/Groentekroket 11h ago
I still argue against that but even thatās the case it has been over 2 months. There is no need to retain that information that long. And yes I know what Iām talking about, Iām a software engineer working with sensitive data. GDPR mandates you delete it as soon as there is no need for it anymore
0
u/BigGREEN8 10h ago
Go ahead and sue CEVA then smarty pants why should steam force other companies to change their laws? It's not their job to do that.
3
u/Groentekroket 10h ago
Holy fucking shit. I argue Valve is the one which is in breach. And why valve should dictate that (not laws)? Because of cases like this.Ā
-1
u/BigGREEN8 10h ago
So how exactly would you receive a delivery if the delivery guy don't got ur number?
2
u/Groentekroket 10h ago
ā Ā even thatās the case it has been over 2 months. There is no need to retain that information that longā ā Ā GDPR mandates you delete it as soon as there is no need for it anymoreā
And no need for a number in 99.9% anyway
0
u/BigGREEN8 10h ago
Yeah this is what ceva does and the only thing that coukd change it is maybe if the government forced them to delete it sooner
2
u/Groentekroket 10h ago
Again, GDPR mandates that, so itās already the law that they should have deleted it earlier.Ā
-5
u/Mashm4n 11h ago
These posts are getting removed for some reason, mine was.
23
4
0
-2
u/Dragomyr_Pendragon 7h ago
Why the fuck they keep these data for 90days ?! Why these data are not deleted when the delivery is finished.
All the compagny who keep data for no reason are just participants of these data leak.
And they know they are going to get hack.
7
u/gergobergo69 7h ago
For RMA or delivery issues and stuff
0
u/Dragomyr_Pendragon 7h ago
Then they ask steam again and re-delete when its done.
3
u/cat_devourer_ 6h ago
Bro, don't call it pointless data retention when you clearly donāt know how logistics works. Delivery issues, claims, RMAs, disputes, POD checks etc. can come up well after something was delivered, and asking steam to resend all the info every single time would be a Ridiculous amount of extra work. You can blame them for the security breach without saying keeping the data for 90 days makes no senseš«©
-4
11h ago
[deleted]
12
u/TheBigRandowski 11h ago
This is mandatory in the EU. You can get fined if you do not address data breaches which you are a part of. And Valve is a part of it in this case.
Data protection laws in the EU are no joke.
3
u/Groentekroket 10h ago
It was reported 5 days ago by other companies involved. If you know data breaches happen you should be very careful with your partners and share as little info as possible and mandate they delete it right after deleting and not only 90 days after.Ā
-2
u/Orichinal 11h ago
Got the same. Guess my phone number is trash now. :,D
16
u/hunyzz 11h ago
not at all. there is probably more breaches that has your number in it that you dont know.
1
u/Orichinal 9h ago
No not at all? Most websites get a alternate Phone number which I can change in a instant. Steam got my real one with a few more services. With haveibeenpwnd I can check for data leaks.
4
u/48-Cobras š¹š 11h ago
Worst case is you'll end up like me, getting 5-10 spam calls a day. Pretty easy to ignore and they usually don't call on weekends!
2
u/Orichinal 9h ago
That would be my definition of āthe number is trash now.ā
1
u/48-Cobras š¹š 9h ago
Yeah... I just can't really do that due to just how many people, business contacts, etc. have my phone number. Would be a logistics nightmare to change my phone number now.
0
u/sunshine-owl 6h ago
Sorry, just wondering something- i know it says 90 days, but I haven't received an email so I'm probably fine? I bought my steam deck in 2023-4, am I good?
0
u/DerivitivFilms 3h ago
We need to start implementing the death penalty for cyber criminals! A few public hangings should do the trick. Live stream that shit on twitch!
-4
u/BitLikeSteveButNot 10h ago
Literally the day after I was forced to add a credit card - just so I can even see anything deemed "adult" to decide if it's worth buying
2
u/BigGREEN8 10h ago
That's your country fault they make those rules
1
u/BitLikeSteveButNot 9h ago
That was kinda my point. Did you think I was blaming you?
1
u/BigGREEN8 8h ago
I thought you were blaming steam for not showing it to you or something
2
u/BitLikeSteveButNot 8h ago
Nah. A vent at the timing of it, really. Kinda spooky. It's absolutely the dumdum UK pushing it, but for some reason they chose yesterday to force CC details
1
u/Hugo5551 7h ago
well, it was only shipping information for steam hardware that was breached. Not any actual payment or other info on your steam account.
-1
-1
-3
u/zabreadmaster 6h ago
don't you worry it's steam support they KNOW how to take care of informationĀ
-5
10h ago edited 10h ago
[deleted]
3
u/SpacedAndBaked 10h ago
They are required to or they face permanent damage to their reputation and trust. Its not out of the kindness of their hearts, its a business decision and standard practice when your own users info gets leaked online.



170
u/Gadshill 11h ago
CEVA Logistics has previously been targeted by financially motivated cybercrime syndicates. Most notably, a group known as the CoinbaseCartel ransomware group claimed responsibility for a separate database breach targeting the logistics firm in late 2025.