PSA: Steam Users Hit by Cyberattack – Expect Fake Messages

PSA: Steam Users Hit by Cyberattack - Expect Fake Messages

You open an email that names the Steam hardware you ordered and quotes your street address. I read Valve’s alert minutes later and felt that small chill that follows a personal data leak. For Steam Machine and Steam Controller customers in Europe, the warning is real and immediate.

Valve says a logistics partner, CEVA Logistics, told them on August 7 that a cyberattack exposed customer records. DigitalFoundry flagged the notice; Valve confirms the breach may include names, national IDs, addresses, phone numbers, email accounts tied to Steam, and purchase details for Steam hardware. Payment and password data were not exposed, Valve says — but that doesn’t make the situation harmless.

A stack of printed labels spilling across a shipping table — how the leak is being handled

I read Valve’s statement closely so you don’t have to parse legalese. CEVA has isolated affected systems, taken them offline, and hired outside investigators. Valve is pressing CEVA for a full accounting and is notifying data protection authorities across the affected countries.

If attackers already have your address and order details, they can make a scam feel like an addressed envelope. That familiarity is their most effective tool.

Was my payment or password data leaked?

Valve’s message is blunt: no payment or account passwords were exposed in the CEVA incident. Still, having your contact and delivery information lets scammers attempt convincing phishing or courier scams that push you to reveal credentials or codes.

A courier leaves a note with your full street — why you should expect fake messages

My inbox and Twitter feeds already show early attempts: emails, SMS, and phone calls claiming to be from Steam, Valve, or a delivery company. Valve warns these messages may quote your address to look legitimate and ask you to confirm delivery, pay a small customs or redelivery fee, or sign in to “verify” an order.

Do not follow links in those messages. Type the address yourself. Real Steam account support only uses help.steampowered.com, store.steampowered.com, www.steampowered.com, or steamcommunity.com. Steam Support will never ask for your password or a Steam Guard code — and neither will a courier. Handing a Steam Guard code over is like a locksmith handing out keys.

What should I do if I get a suspicious message about my Steam order?

Don’t click links or call numbers provided in the message. Don’t send money for customs or “redelivery” fees. Never give your password or Steam Guard code to anyone who reaches out. Instead:

  • Open your browser and go directly to Steam Support or store.steampowered.com.
  • Report the message to Steam Support and to your email/SMS provider.
  • If you suspect your email account has been compromised, treat that as a priority — change passwords and enable two-factor where available.

A company statement lands in my newsfeed — who’s saying what right now

Valve is communicating directly with affected users and regulators while pushing CEVA for details. CEVA has isolated systems and brought in outside investigators. DigitalFoundry and other outlets have circulated Valve’s alert; your best, fastest source for answers remains the official Steam Support page.

I’ll be watching how CEVA and European data protection authorities respond. You should watch your inbox and phone for anything that asks you to act on a Steam order — and treat it as suspicious until verified.

Will companies and regulators do enough to stop these scams before they find new victims?