Valve has alerted European owners of Steam Machines and Steam Controllers that their personal data has been exposed in a recent cyber incident.
DigitalFoundry reports that the breach did not compromise payment or password information, yet it does include a broad spectrum of personal details—national IDs, home addresses, country of residence, phone numbers, email accounts linked to Steam, and records of Steam hardware purchases.
Valve warns users to remain vigilant against deceptive communications—whether email, SMS or phone—that reference their hardware order and masquerade as official messages from Steam, Valve or delivery partners. These fraudulent messages may even echo the user’s address to appear legitimate and could request confirmation of a delivery, payment of a nominal customs or redelivery fee, or a login to “verify” the order. All such messages should be treated as phishing attempts.
Valve is actively engaging CEVA, its logistics partner, to fully assess the scope of the recent cyberattack. The company is notifying data‑protection regulators in every affected jurisdiction, while CEVA has already isolated the compromised systems, taken them offline, and brought in external forensic investigators.
In its official statement, Valve outlined three essential precautions for users confronting suspicious activity:
• Steam Support only handles account issues through the official portal at https://help.steampowered.com/. Any assistance offered via email, Steam Chat, or Discord is a red flag.
• Legitimate Steam login pages reside on store.steampowered.com, www.steampowered.com, steamcommunity.com, or help.steampowered.com. Users should type the address directly rather than clicking on links from unknown sources.
Steam Support never asks for your password or Steam Guard code, and the same rule applies to any official courier. This policy is a cornerstone of Valve’s commitment to safeguarding user accounts and preventing phishing attempts.
If you have additional questions about this incident, the most reliable source for answers remains the Steam Support website.
❓ Frequently Asked Questions (FAQ)
What personal information was exposed in the recent Steam cyber incident?
The breach exposed a wide range of personal details, including national ID numbers, home addresses, country of residence, phone numbers, email accounts linked to Steam, and records of Steam hardware purchases. Payment and password information were not compromised.
Does this data breach affect my payment or account security on Steam?
No, the incident did not compromise payment or password information. However, the exposed personal data could be used by attackers to craft sophisticated phishing or identity‑theft campaigns, so users should remain cautious.
What steps should I take if I receive suspicious messages after this breach?
Treat any unexpected emails, SMS, or phone calls that reference your Steam hardware order or ask for personal details, payment, or a login as phishing attempts. Do not click links, download attachments, or provide any information. Verify the sender by contacting Steam support directly through official channels.
News Source: Destructoid
Comments
Be the first to comment.