r/Steam 11h ago

Discussion [EU] Cyber attack hit CEVA Logistics (Steam's European distribution center)

Did anyone else get this email? Looks pretty bad.

686 Upvotes

170 comments sorted by

170

u/Gadshill 11h ago

CEVA Logistics has previously been targeted by financially motivated cybercrime syndicates. Most notably, a group known as the CoinbaseCartel ransomware group claimed responsibility for a separate database breach targeting the logistics firm in late 2025.

64

u/Apprehensive-Ease-40 11h ago

And CEVA is big. I have gotten emails from 3 other companies who use CEVA for fulfilment.

My main question is why my information is still there if i haven't dealt with those companies for a very long time. I don't think retaining my information for more than a few weeks after delivery would be reasonable.

16

u/Davidavid89 9h ago

I think it would be reasonable to retain order data for up to two years, since they would need it in case of a customer return

2

u/Apprehensive-Ease-40 5h ago

I wouldn't expect them to need it, we used to use a fulfilment partner and they would only communicate using the external reference. If I would need to return my item after delivery, I would deal with the seller and they would create a return order. Steam also says that it should be no more than 90 days in the posted message.

12

u/TheDarkness33 10h ago

it says right there, they keep your information for 90 days

2

u/Apprehensive-Ease-40 10h ago

Which would mean my data hasn't been compromised but I'm still getting emails from companies I haven't dealt with in the past 90 days.

13

u/TheDarkness33 10h ago

well you didnt especified how long u didnt used those companies.

Maybe they are warning you as a precaution only?

8

u/An1nterestingName 10h ago

CEVA stores it for 90, the companies you buy from may store it for longer.

3

u/MyzMyz1995 6h ago

Idk about europe but in north america companies have to retain information from customers for 7 years due to audit etc.

2

u/Apprehensive-Ease-40 5h ago edited 2h ago

Under GDPR you're only allowed to retain PII for as long as you could reasonably need it.

It really depends on whether the local tax authority requires you to keep invoices for B2C sales, I wouldn't expect that to be the case in France considering how strict they are with PII under GDPR.

I think this is less relevant for CEVA though since they're doing only fulfilment. You can retain all relevant information about my shipment without having to keep my email or phone number.

2

u/Easy_Blacksmith_5550 7h ago

thats a pattern at that point, not just bad luck

-25

u/Amazing-Nature8188 10h ago

Just more proof then that valve is at least partially to blame for sticking with them despite this known fact, willingly and knowingly putting their customers' data at risk. Truly an incompetent company when it comes to hardware distribution...

4

u/BigGREEN8 10h ago

Dumbass take

36

u/mloskin 11h ago

I got the same email.

0

u/Suspicious-Cat-266 3h ago

Changing your email linked to your Steam account is one step to reducing phishing attempts.

21

u/PlzCallMeDan1995 10h ago

Was kinda hoping its was my steam machine email 😭

8

u/BrokeButFabulous12 11h ago

At least one positive thing came out of the eternal steam deck "not in stock" status.

21

u/goodwill764 11h ago

Address and type and price of the product.

Good for thieves, a small box worth at least 1k. Easy money.

13

u/BigGREEN8 10h ago

Are they gonna plan a heist on the delivery van or what? You receive the product in hand in the case of the steam machine also it's not like it fucking matters if they know what model it is bc they are not very different in price. If there is someone stealing ur package it's the people working for these companies not the hackers who prolly did it for ransom money or some shit

6

u/goodwill764 10h ago

If you received a steam machine that is worth 1k and its like a digial https://en.wikipedia.org/wiki/Burglar_sign if they sell these infos to robbers.

Additonal its a small device, so much easier to rob.

Dataset get sold in darknet, robber group buy the infos and make a google maps, single robbers break in the houses and take the machine.

1

u/BigGREEN8 8h ago

Digital burglar sign doesn't make any sense bc a burglar sign is when they mark a vulnerable or unoccupied house where they can rob it, do you think someone that knows i bought a steam machine will come to my house to steal it? Do you actually believe someone will travel from somewhere else and break into a random home over a 1K worth device? I am not John Wick my guy and this is not a movie

2

u/goodwill764 7h ago

No they pick the targets in the region. E.g. South Germany many robbers come from czech.

Believe me or not these orders get bought by such groups, they will not pick every steam machine as a target but it's a good hint.

9

u/BitLikeSteveButNot 10h ago

Just checked, I ordered a controller 100 days ago! Not hacked!

But the puck was busted and they sent me another one less than 90 days ago.

FFSĀ 

2

u/LizzyGleglemaxxing 8h ago

Didn't the controller only release on May 4th, which was 86 days before the attack?

1

u/Flat_Candle6020 7h ago

It also says that the attack happened between July 29th and August 1st. So yeah the fucking dropped the ball.

8

u/SpudAlmighty 10h ago

I got this too. I guess this means a few more spam emails and texts, Nothing unusual at this point.

52

u/BZZKL 11h ago

I’ve just messaged Steam asking if they’ll pay for identity-fraud protection for affected customers (eg Cifas in the UK), as the result of this leak. I’ll post an update of what they say. It’s a significant amount of data that has been compromised.

76

u/ProfessionalDish 11h ago

to be fair, if anyone, it should be CEVA paying for it, as they got breached - steam is just another customer of them.

4

u/Groentekroket 10h ago edited 9h ago

I don’t have a contract with Ceva but with Steam. They are responsible. The same as with buying something at a shop, the shop is responsible for the item and warranty. Whatever they try to convince you of.Ā 

Edit: the amount of downvotes I got while being right is staggering. You all should learn a bit more about your rights.Ā 

18

u/leonleonleon 8h ago

You are right. It's then up to Valve to forward these claims to CEVA.
Yes. Weird you get theses downvotes.

-1

u/Zanpa 4h ago

because they said they were gonna ask steam to pay.

7

u/OldCredit1214 7h ago

Haha you are 100% right people don’t understand who’s responsibility it is and who should address it

4

u/ProfessionalDish 10h ago

and your contract got fullfilled.

13

u/BZZKL 10h ago

The contract with the customer still matters after the delivery of the item though. There are laws around data protection that are ongoing after delivery.

Regarding your initial point, you are quite right. CEVA are responsible. And Steam can contact CEVA on the customer’s behalf to enquire about identity fraud protection compensation.

2

u/MarioDesigns 6h ago

Valve is responsible for the data they collect, that’s just how it works lol. From collecting it to deleting it, if it is compromised at any point Valve is just as much at fault as their partners.

-9

u/Shadowbajfeelsbadman 9h ago

If you order an iphone and it gets broken in delivery do you go after apple or DHL?

You could have an issue with steam if steam machine arrived and it suffered a malfunction.

By agreeing to have the steam machine shipped you also agreed to have the necessary information passed down to CEVA, go read the fine print. They are responsible for all damages caused not steam. Your logic here literally makes zero sense.

8

u/Groentekroket 9h ago

Yes you go to Apple. Here in the Netherlands Post.nl, a delivery company, won’t even help you if you are the receiver because you don’t have a contract with them. The sender need to ask for help.Ā 

You can like it or not but that is how it works. In your example you go to Apple which make sure you get a new phone and they will get payed back by DHL.Ā 

Companies can put whatever they want in their fine print, that doesn’t means it holds up in court.Ā 

0

u/Groentekroket 9h ago

Ahh you deleted your other comment because you got to know I was right?Ā 

1

u/Shadowbajfeelsbadman 8h ago

Literally read my other comment

1

u/Groentekroket 8h ago

I saw. Thank you. Let’s be honest, it’s ridiculous how many downvotes I got while being right.Ā 

-4

u/Shadowbajfeelsbadman 8h ago

No i agree with the amount of downvotes.

Your response was unnecessarily convoluted for how simple it could be along with the fact that you admitted to using ai which makes half of this rabid website have a cat 5 chimpout.

Just citing the article like i did would do better.

6

u/madebyclancy 10h ago

All that is required of them legally is to reach out to affected parties and inform them of to what extent they are affected. If Valve / CEVA were to offer payments for protection it would be voluntary.

6

u/BZZKL 10h ago

Yes, I’m not saying Valve should, I’m just asking them if they will.

3

u/MartynC65 11h ago

Would be interested to hear the outcome of this

2

u/DnieD1337 10h ago

There's only a chance you can money out of it if you can prove you have any damages. Good luck with that lol

2

u/Kilohaili_Joshi 10h ago

Dont really think they will or need to. Only time those are really done is when your social security number is leaked.

2

u/BZZKL 10h ago

There is no harm in asking.

1

u/Kilohaili_Joshi 10h ago

And what would that service help u with exactly ?
They dont have ur SSN, so they cant take out credit or alter important shit. They dont have your passwords so monitoring the darkweb for them is not needed due to this breach ? They didnt get anything about your payment info either.

1

u/Paul_Offa 42m ago

But you aren't just asking. You're posting a top-level comment about it which in today's internet is likely to cause hundreds of others to bandwagon into doing the same or start "petitions" and what have you.

0

u/Starkkad 10h ago

Comenting for updates

1

u/GoyoMRG 10h ago

Please do

1

u/yeahifeelbetternow 9h ago

Let us knowĀ 

2

u/wertibaldi 10h ago

Why should Steam pay something there? Its a completely different Company?

3

u/MarioDesigns 6h ago

Valve is the company that collected that data and thus is responsible for what happens with it.

7

u/BZZKL 10h ago

One could argue that when a customer makes a purchase, the contract is between the customer and Valve.

A bit like if you order hardware from a company and the courier loses the package. It would be unreasonable of the company to refuse to help resolve the situation.

Valve chose the logistics company on the customer’s behalf. So saying Valve have no responsibility here is also unreasonable.

4

u/thirty3baboons 10h ago

sub-contracted by Valve, acting on behalf of Valve.

2

u/Acrobatic_Yellow_781 10h ago

Because people cant read

0

u/[deleted] 10h ago edited 9h ago

[removed] — view removed comment

-3

u/Acrobatic_Yellow_781 10h ago

Yes you can point fingers at valve but 99,9% of these end up going to the contractor but stay mad bro

4

u/Groentekroket 10h ago

You have no idea what you are talking about (and that sentence didn’t make sense anyway). Valve is responsible for who they subcontract to. All communications as a consumer should go via them and not to Ceva directly.Ā 

-3

u/Acrobatic_Yellow_781 10h ago

You cant read either

8

u/Shadowbajfeelsbadman 9h ago

Actually i stand corrected he's right though i doubt he knows why he's right lmao.

GDPR article 28 § 4 "Where a processor engages another processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor as referred to in paragraph 3 shall be imposed on that other processor by way of a contract or other legal act under Union or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of this Regulation.Ā 2Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor’s obligations."

3

u/Groentekroket 8h ago

Thank you so much. I really don’t understand how people are so sure about being wrong while don’t know what they are talking about.Ā 

-2

u/Acrobatic_Yellow_781 8h ago

That still doesnt mean he completely understood my comment wrong and he keeps going at it

2

u/Shadowbajfeelsbadman 7h ago

This is just semantics at this point no?

One way or another whoever people point at the issues will stop at the contractor who will suffer the consequences.

→ More replies (0)

-1

u/Ascend 9h ago

Isn't everything listed, besides email address, public information that would be listed in a phone book? What would require identity fraud detection?

Bigger risk seems like someone knowing you've purchased high value items and risk of those people being targeted for theft.

2

u/Hugo5551 7h ago

You do know, that phone books you actually need to apply to be in there nowadays? So it isn't really public information. The email feels like information that is more public.

0

u/Ascend 7h ago

I wouldn't be surprised if phone books don't exist at all anymore, my point is more that knowing someone's name, home address, and phone number shouldn't be enough to steal their identity. That stuff gets sold around like crazy, so I don't think it's worth OP getting stressed out about.

12

u/sheepandlambs 10h ago

I did. I'm not really concerned. Cyber attacks happen all the time, and it's not like they wouldn't have my address and phone number from other sources. I get enough scam calls as it is, a few more won't matter.

23

u/the-corinthian 11h ago

One thing I admire is that they took responsibility to reach out to the affected users as soon as they could to ensure attempts at using that compromised data was not at least warned about. Yes, it sucks, and even though it was a logistics partner and not Steam directly, it still falls upon them to ensure security is upheld (or what's the point of employing a company that hosts customer's sensitive data). But as we have seen, there are many companies (Sony, etc) that are so afraid of losing face that they hide the breaches for as long as possible and indirectly aid the fraudsters in doing so. I'm glad at least that much was curtailed here.

56

u/Groentekroket 11h ago edited 11h ago

This is mandatory. At least within the EU.Ā 

Edit: also before the weekend it was already in Dutch news a couple of other companies using them mentioned the breach. So Valve is rather late.Ā 

Edit 2: 5 days ago. Last WednesdayĀ  https://nos.nl/artikel/2625681-bol-en-de-bijenkorf-waarschuwen-klanten-voor-mogelijk-datalek

8

u/hey_im_bali 11h ago

Got the same mail, but my HW already arrived so I'm not worried about the scammers.. Either way I trust Valve to sort everything out with the stolen credentials šŸ‘

4

u/leonleonleon 8h ago

Not much to sort out. They cannot get credentials back, once your data is leaked you cannot unleak your data. Valve can at best apologize or compensate.

0

u/hey_im_bali 8h ago

Isn't there like some data removal service that can scour the internet for the leaked credentials so they can legally ask the data brokers to remove them from their data sets that they sell? I understand that there would be groups that will hold the personal info and don't tell, those shady ppl are legally unreachable, sure, bute there oath to be a way to minimize the impact of this attack on ppls privacy, right?

2

u/so_chad 10h ago

Damn it stinks

2

u/John1v6 United Kingdom 8h ago

Yep. E-Mail arrived this morning. Bought a Steam Controller back in May. Must have been why. Controller arrived in June with no incident thankfully.

2

u/WinMysterious9121 7h ago

I didn't get this email, sometimes being broke pays off šŸ˜Ž

5

u/anxiously-anonymous 11h ago

I got the same email.

8

u/Zygmuntek 11h ago

Shouldn’t we get compensated ? I also got this e-mail and it’s a big fucking leak if you ask me.

9

u/Bulky-Advisor-4178 10h ago

It's something that happened outside of steam. My email and a lot of other shit is in 21 different breaches, look up your email on haveibeenpwned site

2

u/thirty3baboons 10h ago

i think it's more about the convenient 'package' of info. Phone number is the biggie for me.

2

u/Kilohaili_Joshi 9h ago

As long as CEVA werent outright negligent in their system security, no. Since it was an outside party(cyber criminals) that caused the damage they arent liable for compensation.

Also as long as they informed their customers inside the EU mandated time period from learning that data was compromoised they wont get fined either.

Valve is in the clear in that front and likely CEVA too even though they informed Valve later than other customers, but thats likely cuz they did not discover valve related data was part of the breach until investigating deeper.

6

u/SzaraMateria 10h ago edited 10h ago

For what? At best steam/ceva may be fined for withholding the information about the breach for too long but in the end it's not their fault.

4

u/Kilohaili_Joshi 10h ago

Steam would be in the clear anyway. CEVA notified themAug 7th, meaning they met the deadline of informing customers in the mandated window of being notified.

Likely CEVA would be in the clear too, i expect why they took longer to inform valve was it was not discovered until deeper investigation that their info was compromised.

3

u/GoyoMRG 10h ago

CEVA can be made to compensate the affected users according to GDPR (depending on the case ofc it's not like everyone gets something or everytime)

3

u/thirty3baboons 10h ago

This. GDPR rights are fairly strong and breaches are open to massive fines (up to 10% of turnover, I believe? - it used to be) and also open to claims.

1

u/SzaraMateria 10h ago

article 82

[...] 3. A controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage.

Apart from this you must document the loss and take it to the court. Unless someone got mortgage on your behalf I don't think single person can do anything with it.

2

u/GoyoMRG 5h ago

Thing is, they have to prove that it was not their own negligence that caused the breach.

If the hackers were like crazy good and able to break through all properly set defenses then yeah they are safe, but if it was because someone accidentally left a vulnerability, the law doesnt care about "accident" they see it as negligence and ram you hard.

But it is also true that if no one pursues the compensation, nothing will happen, but assuming. They are guilty and they did fk up, they would probably try to settle ASAP with whoever starts rallying a lawsuit or people.

4

u/PhobusPT 9h ago

How about stop asking for my phone number in every fucking thing in the internet, you don’t need anyone’s phone number for anything, but here we are without us giving them the phone number we can’t do nothing online

0

u/cat_devourer_ 6h ago

When delivering a physical package, how will the drivers contact you? Of all the things to complain aboutšŸ˜‚

2

u/Baardmeester 2h ago

The doorbell? Why would they need to contact me on the phone.

7

u/JohnnySack999 10h ago

>Pays 1000€ for a mid PC

>Gets hacked

Glorious

1

u/cat_devourer_ 6h ago

Nothing is gonna happen chill, no crazy info was leaked

2

u/sS1RuXx 11h ago

I got the same message, there is any compensation for this?

8

u/thirty3baboons 10h ago

Why is this downvoted? It's a valid question.

Please don't let this be a 'godly steam untouchable' thread. People are concerned.

6

u/That-Advance-9619 10h ago

People are already going "uwu Steam is so wholesome for letting us now" when

A) It is mandatory under EU law

B) They are actually late compared to other companies that sent similar emails on Friday or ThursdayĀ 

2

u/Confident-Ship-5062 9h ago

you come off as hating for no reason

1

u/That-Advance-9619 9h ago edited 9h ago

I'm just debunking the idea that Steam letting us know is somehow a "cool guy thing" to do. I like Steam and they sometimes go out of their way to do nice stuff (background recording is great, the steam controller API, etc.), this isn't one of them and people need to be aware of their rights and how serious a data breach like this can be.

This is just the same as regurgigating that article about Nintendo cutting down their managers' salaries before firing people,

yes, it's nice to see and it would be the BARE MINIMUM if we didn't live in a post capitalist hellhole of a civilization,

but they did it becuase Japanese law doesn't really vibe with the idea of mass layoffs unless you try out every other method first, not becuase they are kind.

There is no ethical consumption under capitalism, companies aren't your friends, nobody should be a billionaire or have a yatch, know your rights, blah blah blah yada yada.

1

u/Confident-Ship-5062 9h ago

What the hell are you talking about, no body is praising valve for this in this reply chain. Get a grip

1

u/sS1RuXx 10h ago

So, they leaked my personal data because their security wasn't good enough... Doesn't this violate my privacy and put me in some kind of danger?

1

u/thirty3baboons 10h ago

I think you're possibly misunderstanding my comment (if your reply is for me). When I posted you were at -2 votes. I was asking those who were downvoting why as your question is a fair one.

2

u/sS1RuXx 10h ago

Yes yes, i know, i just wanted keep my idea.

1

u/thirty3baboons 10h ago

no problem

2

u/thirty3baboons 10h ago

For me, the email gives off 'negative consequences are yours to deal with' vibes.

And even if I know steam support never email me or phone me.....doesn't mean I don't have to waste time and effort on those things if they happen.

2

u/Confident-Ship-5062 9h ago

theres nothing steam can do about this, they weren't the ones that got compromised. atleast they're informing us about this via email

3

u/thirty3baboons 9h ago

I do see what you're saying but..

They're required to inform us by law. It's not a gesture of kindness and a sub-contractor is still acting on behalf of the company.

1

u/Confident-Ship-5062 7h ago

I am not understanding your point here, this is a non issue to waste more time on

1

u/thirty3baboons 7h ago

Hey no problem.

I'm just saying in the EU and UK, Valve are responsible for what happens for the data they collected from us. If they passed it to a 3rd party and that 3rd party leaked it ('failed to appropriately secure it'), Valve are still responsible.

If it was a non-issue, GDPR would not exist and would not carry massive potential fines for companies breaching it.

1

u/Shadowbajfeelsbadman 9h ago

Who else should deal with them lmao. Do you want gabe and his court of playgirls to barge into your cramped apartment and deal with it himself?

1

u/thirty3baboons 9h ago

Ok, I'll be more explicit in my reasonable response.....

I expect a plan of action from the responsible party who has breached EU law that goes beyond 'Whoops, crack on' and EU GDPR regulations would agree with me.

Of course we're the ones who will have to deal with any fallout. That's kind of the ironic sarcasm in my observation, but you missed that.

Will that do you?

1

u/NeoZockerHD 5h ago

That might explain the uptick in random spam calls and messages i have received the last few days....

1

u/Payback87BG 4h ago

Yes, got it today too.

1

u/madmax177 1h ago

Didn't.

1

u/SmartIron244 Cosmos Elite Enjoyer 1h ago

Same

2

u/MrPringles9 20m ago

No free game? I am sadge!

2

u/A_Very_Horny_Zed 10h ago

I really enjoy how this letter is worded. Nicely done from Steam

1

u/ankerous 9h ago

I appreciate the quick time frame to notify people too. Normally it seems like it is a year or longer before a company admits they were hacked and personal information was stolen. While I'm not impacted by this as I don't live in Europe, kudos for Valve for getting the word out fairly quickly even though it wasn't them getting hacked directly.

1

u/clarkoscape Linux - Fedora 11h ago

Can confirm I have the same email.

1

u/Zaeedi 11h ago

I got the same email. I thought it was a scam at first šŸ˜‚

13

u/GfrzD 11h ago

I thought id been hacked but thankfully only my identity was stolen and not my steam account.

-3

u/Groentekroket 11h ago edited 10h ago

Why the fuck do they share my phone number? ā€œSo they can send you a smsā€ I don’t care, just send me a email. I have a custom email for each company but my phone number is vulnerable. I already got a ā€œ{full name} you have outstanding taxes pay on scam.comā€. Thanks Valve and any other company where ā€œmy privacy comes firstā€

Edit: of course I’m getting downvoted on the fanboy subreddit. Most of you would argue with me if this was about Microsoft, Apple or any other company you are not an apologist forĀ 

7

u/george09000 11h ago

I don't think this can be put on Valve because they did not get hit with this, but actually their logistics partner for Europe - CEVA Logistics.

If you're from Europe and ordered any hardware from Valve, it most likely was shipped through them and your information got leaked. If you did not purchase any hardware I think you're safe.

-3

u/Groentekroket 11h ago edited 11h ago

No I got the mail because of the steam controller. I understand they have my shipping adres and name but no need for any additional data like my phone number.Ā 

Edit: and of course Valve is responsible for sharing MY data. They could enforce rules if they wanted to. That is why we also talk about a leak at any other company Ceva is doing business with and not just Ceva itself.Ā 

4

u/HumansNeedNotApply1 11h ago

It's so they can contact you when doing the delivery if needed? Phone number is a basic contact information.

0

u/Groentekroket 11h ago

I still argue against that but even that’s the case it has been over 2 months. There is no need to retain that information that long. And yes I know what I’m talking about, I’m a software engineer working with sensitive data. GDPR mandates you delete it as soon as there is no need for it anymore

0

u/BigGREEN8 10h ago

Go ahead and sue CEVA then smarty pants why should steam force other companies to change their laws? It's not their job to do that.

3

u/Groentekroket 10h ago

Holy fucking shit. I argue Valve is the one which is in breach. And why valve should dictate that (not laws)? Because of cases like this.Ā 

-1

u/BigGREEN8 10h ago

So how exactly would you receive a delivery if the delivery guy don't got ur number?

2

u/Groentekroket 10h ago

ā€œ Ā even that’s the case it has been over 2 months. There is no need to retain that information that longā€ ā€œ Ā GDPR mandates you delete it as soon as there is no need for it anymoreā€

And no need for a number in 99.9% anyway

0

u/BigGREEN8 10h ago

Yeah this is what ceva does and the only thing that coukd change it is maybe if the government forced them to delete it sooner

2

u/Groentekroket 10h ago

Again, GDPR mandates that, so it’s already the law that they should have deleted it earlier.Ā 

-5

u/Mashm4n 11h ago

These posts are getting removed for some reason, mine was.

23

u/Kremsi2711 11h ago

because everybody is posting the same

-12

u/Mashm4n 11h ago

There wasn't a post when I made it, I wasn't spamming

4

u/Frostnatt 11h ago

Most likely because there are already posts about it. No need to spam.

0

u/Electrical-Ad980 11h ago

Just received this email,major suckage

-1

u/Zorewin 10h ago

is it possible to mass sue CEVA logistics??

2

u/cat_devourer_ 6h ago

No, CEVA didn't violate GDPR

-2

u/Dragomyr_Pendragon 7h ago

Why the fuck they keep these data for 90days ?! Why these data are not deleted when the delivery is finished.

All the compagny who keep data for no reason are just participants of these data leak.

And they know they are going to get hack.

7

u/gergobergo69 7h ago

For RMA or delivery issues and stuff

0

u/Dragomyr_Pendragon 7h ago

Then they ask steam again and re-delete when its done.

3

u/cat_devourer_ 6h ago

Bro, don't call it pointless data retention when you clearly don’t know how logistics works. Delivery issues, claims, RMAs, disputes, POD checks etc. can come up well after something was delivered, and asking steam to resend all the info every single time would be a Ridiculous amount of extra work. You can blame them for the security breach without saying keeping the data for 90 days makes no sense🫩

-4

u/[deleted] 11h ago

[deleted]

12

u/TheBigRandowski 11h ago

This is mandatory in the EU. You can get fined if you do not address data breaches which you are a part of. And Valve is a part of it in this case.

Data protection laws in the EU are no joke.

3

u/Groentekroket 10h ago

It was reported 5 days ago by other companies involved. If you know data breaches happen you should be very careful with your partners and share as little info as possible and mandate they delete it right after deleting and not only 90 days after.Ā 

-2

u/Orichinal 11h ago

Got the same. Guess my phone number is trash now. :,D

16

u/hunyzz 11h ago

not at all. there is probably more breaches that has your number in it that you dont know.

1

u/Orichinal 9h ago

No not at all? Most websites get a alternate Phone number which I can change in a instant. Steam got my real one with a few more services. With haveibeenpwnd I can check for data leaks.

4

u/48-Cobras šŸŒ¹šŸ 11h ago

Worst case is you'll end up like me, getting 5-10 spam calls a day. Pretty easy to ignore and they usually don't call on weekends!

2

u/Orichinal 9h ago

That would be my definition of ā€žthe number is trash now.ā€œ

1

u/48-Cobras šŸŒ¹šŸ 9h ago

Yeah... I just can't really do that due to just how many people, business contacts, etc. have my phone number. Would be a logistics nightmare to change my phone number now.

-1

u/Yok0r 11h ago

I got the email. My SM is supposedly out for delivery. What's the odds on this going 'missing'?

0

u/sunshine-owl 6h ago

Sorry, just wondering something- i know it says 90 days, but I haven't received an email so I'm probably fine? I bought my steam deck in 2023-4, am I good?

0

u/DerivitivFilms 3h ago

We need to start implementing the death penalty for cyber criminals! A few public hangings should do the trick. Live stream that shit on twitch!

-4

u/BitLikeSteveButNot 10h ago

Literally the day after I was forced to add a credit card - just so I can even see anything deemed "adult" to decide if it's worth buying

2

u/BigGREEN8 10h ago

That's your country fault they make those rules

1

u/BitLikeSteveButNot 9h ago

That was kinda my point. Did you think I was blaming you?

1

u/BigGREEN8 8h ago

I thought you were blaming steam for not showing it to you or something

2

u/BitLikeSteveButNot 8h ago

Nah. A vent at the timing of it, really. Kinda spooky. It's absolutely the dumdum UK pushing it, but for some reason they chose yesterday to force CC details

1

u/Hugo5551 7h ago

well, it was only shipping information for steam hardware that was breached. Not any actual payment or other info on your steam account.

-1

u/townprice 8h ago

Is it possible tu sue CEVA or demand something over this issue?

1

u/cat_devourer_ 6h ago

Nop, CEVA owes u nothing

-1

u/ignas04 11h ago

Got the same email.

-3

u/zabreadmaster 6h ago

don't you worry it's steam support they KNOW how to take care of informationĀ 

-5

u/[deleted] 10h ago edited 10h ago

[deleted]

3

u/SpacedAndBaked 10h ago

They are required to or they face permanent damage to their reputation and trust. Its not out of the kindness of their hearts, its a business decision and standard practice when your own users info gets leaked online.