Valve Warns Steam Machine Buyers of Address Scams
Valve is warning Steam Machine buyers that scammers have accessed their addresses following a cyberattack on CEVA Logistics, the firm responsible for shipping Valve hardware across Europe.
What Happened?
- Breach: A security breach at CEVA Logistics exposed customer data including names, countries, street addresses, phone numbers, and email addresses.
- Timing: The incident occurred between July 29th and August 1st, with CEVA confirming the breach on August 7th.
- Affected Companies: In addition to Valve, affected organizations include Bol, De Bijenkorf, ING Bank, Ace & Tate, and Ajax Football Club.
What to Do?
- Fake Messages: Customers should expect fake messages regarding their orders, which may seem legitimate by quoting the customer’s own address.
- Treat as Fake: Valve advises treating all such messages as fraudulent.
- Official Support: Steam support handles issues only through its official help page, never via email, Steam chat, or Discord.
- No Action Required: There’s no need to change passwords or settings, as the breach did not reach the customer accounts.
The Widening Impact:
The CEVA Logistics breach highlights the interconnectedness of digital supply chains. With operations spanning over 1,000 warehouses and handling millions of shipments annually, a single intrusion can cascade through various organizations, underscoring the digital supply chain security challenges we face today.