Steam hardware shipper breach leaks customer data, including names and addresses

A breach at Valve's European shipping partner CEVA Logistics exposed customer names, addresses, phone numbers, and email addresses for Steam hardware orders, with no impact to payment information or account credentials. This third-party supply chain vulnerability highlights the expanding attack surface for technology organizations and the increased risk of social engineering attacks targeting affected customers. IT leaders must reassess vendor security requirements, implement stricter data minimization practices with logistics partners, and prepare incident response protocols for supply chain breaches that extend beyond direct corporate systems.

Emma RothThe Verge2 min read
Read full article
Steam hardware shipper breach leaks customer data, including names and addresses
Valve says a data breach may have exposed the personal information of customers who ordered its Steam hardware in Europe. In an email sent to users, Valve says its European shipping partner, CEVA Logistics, suffered a data breach that may have included customer names, addresses, phone numbers, and email addresses. The breach at CEVA occurred between July 29th and August 1st, weeks after Valve began taking reservations for its new Steam Machine and Steam Controller. Valve adds that European customer data "was likely compromised" as part of the breach, as CEVA stores "delivery-related information" for up to 90 days after orders. … Read the full story at The Verge.