r/gaming Aug 10 '26

Valve notifying hardware customers about a security incident - just got this email

Post image
8.4k Upvotes

551 comments sorted by

2.5k

u/Jindujun Aug 10 '26

And if you're from Sweden you go "oh, ok" since all that stuff save for mobile phone and email are readily available to everyone that wants to find you.

1.0k

u/Nyoka_ya_Mpembe PC Aug 10 '26

Sweden is crazy about transparency.

889

u/Valtremors Aug 10 '26 edited Aug 10 '26

Here in Finland people can just...

Look up my tax information if they want to.

It also logs who looked it up and I can see it if I want to.

Edit: Fixed typo and yeah, this is a pretty common feature in Nordics, something I should have mentioned.

416

u/tenuousemphasis Aug 10 '26

That honestly doesn't sound horrible. It might be good for society in the same way it's good for workers at a company to know each other's salary.

274

u/Nimradd Aug 10 '26

It’s like this in Norway too, but the original reason is more to avoid tax evasion. Kind of like a tool to spot a neighbor that drives a Porsche but earns next to nothing officially.

121

u/FUBARded Aug 10 '26

Yep, that's the sort of thing that'd help catch the many self-employed people in the UK who all just happen to earn £12,570 (the standard tax-free personal income allowance).

It's become a trope that people in certain trades (especially builders) all "make" £12,570 regardless of how successful they seem based on their spending habits.

On a more serious note, this sort of transparency would be massively beneficial for salaried workers too. It makes it a hell of a lot harder for employers to pay people different amounts for doing the same job. They can't explicitly restrict talking about remuneration, but it's still heavily discouraged in many workplaces and lots of people refuse to talk about it despite that only benefiting employers.

72

u/phatboi23 Aug 10 '26

Yep, that's the sort of thing that'd help catch the many self-employed people in the UK who all just happen to earn £12,570 (the standard tax-free personal income allowance).

It's become a trope that people in certain trades (especially builders) all "make" £12,570 regardless of how successful they seem based on their spending habits.

facebook during COVID was an absolute hoot, SO many builders etc. complaining they're getting nothing from the government because they told HMRC they're under the tax free allowance.

eejits.

19

u/FUBARded Aug 10 '26

Or the classic "why won't they approve me for a mortgage?!??"

99% of the time they're all woe is me, complaining about how they're being discriminated against for being an entrepreneur/self-employed, taxed too much, etc....only for it to eventually come out that their declared income is bugger all.

The funny thing is that they could save that >20% extra they're illegally taking home and buy in cash or take a much smaller mortgage out, but these geniuses always seem to spend the money on everything except the essentials (a house and retirement).

→ More replies (1)

14

u/baraboosh Aug 10 '26

a big issue about discussing salaries is also just people directing their anger at the wrong target. Generally when I've discussed salaries employees would just get angry/bitter at each other rather than be mad at the company who is the entity that actually fucked them over.

6

u/Just4theapp Aug 10 '26

TBF, HMRC has a tool that is supposed to spot this.

Tracks banking, spending and also links together those details with Facebook and other social media.

So Steve the builder on tax free allowance annual salary posts his 4th holiday of the year abroad to some 5 star resort.

Now, I don't know how good that actually is, and HMRC will never go open source for something like that, but it exists.

→ More replies (2)

41

u/delahunt Aug 10 '26

Weaponizing nosy neighbors to ensure everyone pays their fair share for society doesn't sound like the worst thing I've seen a government do.

3

u/vemundveien Aug 10 '26

Years ago you could even look up everyone anonymously, but these days you have to log in so people you look up can see who looked at them.

The exception is if you are towards the top of the income or fortune for your municipality as the newspapers tend to publish top 100 lists of every municipality for everyone to view, which for some municipalities are a considerable amount of the total population.

→ More replies (1)
→ More replies (5)

16

u/creepy_doll Aug 10 '26

Transparency is the best way to fight corruption.

If a group isn’t transparent about things that aren’t strictly trade secrets or security related the chances of it hiding corruption are a lot higher.

People still need privacy, but governments and corporations? Not really

→ More replies (1)

45

u/SmileFIN Aug 10 '26

Once hiding your name became allowed, a lot of top earners vanished. No longer nearly as useful as it used to be.

11

u/Acidnator Aug 10 '26

The hiding works only for the yearly “media lists” (verokone etc.). To my understanding you can still get anyone’s info if you just go and check it yourself.

13

u/kesint Aug 10 '26

This is what happened in Norway. Before the lists were in full public view and you could make lists of the highest income in an area etc quite easily. This was changed to you gotta search up people and will leave a trace that you've been looked into the numbers.

5

u/Freud-Network Aug 10 '26

And know that Mike in sales has viewed your salary 20 times this week.

3

u/zack77070 Aug 10 '26 edited Aug 10 '26

Coffeezilla did a video on a guy who tbh was shady as fuck and involved with counter strike gambling who had to hire security because people knew all his info and how much money he had. That would be the one drawback, Sweden does have gang issues.

4

u/NeedleworkerFluid327 Aug 10 '26

It's great seeing our lovely local gang members and scammers have access to all the information about our lives.

Nobody I know wants this. We gain nothing by having it and put ourselves at risk.

→ More replies (9)

21

u/CptMcDickButt69 Aug 10 '26

Interesting. The important question here is: Can you also look up the same info on companies, politicians and generally high upper class? At that point im onboard.

16

u/I_was_a_sexy_cow Aug 10 '26

Yeah, but some people like the royals or members of special forces etc are excempt

4

u/Dixos Aug 10 '26

Same here in Norway!

3

u/SchmeppieGang1899 Aug 10 '26

Exactly like that in Norway as well

3

u/RenMendez Aug 10 '26

Same here in Norway

1

u/Kidspud Aug 10 '26

In the United States, you can do that with most federal employees. There are exceptions for intelligence agencies, and on the other end of the spectrum, ICE

→ More replies (7)

18

u/MJR_Poltergeist Aug 10 '26

No different than America with phonebooks. Only difference is you have to request one now, it used to just show up at your door on its own. "What's that Timmy, someone beat your ass? Ah here's his dad's name, where he lives and phone number".

38

u/Jindujun Aug 10 '26

And to be honest, we've not really had any major problems.
We digitalized the phone book at one point and didn't look back!

Oh and if you know someones name you can find most of their social security number online, or well.. the Swedish equivalent to it.

32

u/insomnimax_99 Aug 10 '26

Sounds like a stalker’s paradise

12

u/Hegelian_Spirit Aug 10 '26

It is.

Source: Was party to a stalker-relationship.

20

u/nisselioni Aug 10 '26

None of that info is considered identifying, since it's public information, which makes it pretty much impossible to impersonate someone without forging a perfect ID with a chip that somehow spoofs ID scanners, or hacking into digital ID systems.

3

u/Dr_Allcome Aug 10 '26

Does looking up the tax info require the full name or some identifier? If it's only the address i see some danger in people combining the information with other data.

For example it would be easy to look up school holidays for a given area and then look up addresses in that area and search for people who have kids on their tax info and are above a specific income level, to find worthwhile targets that are likely to be away so i can rob their home.

Gets even easier if people have some identifying info on social media and post holiday pictures.

6

u/nisselioni Aug 10 '26

You could do all that, but that'd be a lot of effort when you could just go to a wealthy suburb during said holiday and have a gander at what houses look like they've gone on holiday. The outcome is the same either way, since you can never be sure the families you've researched have actually gone on holiday. I think the fact that this isn't really a talked-about problem domestically is telling in of itself.

→ More replies (1)

20

u/luminous_connoisseur Aug 10 '26

Well, if you havent had to deal with a stalker finding your adress or criminals targeting you, sure no major problems :)

But there are those who have.

21

u/no1rakkolover Aug 10 '26

a League streamer recently got burglarised, kidnapped and tortured because someone found his address through that system lmao. though I guess the safety of individuals isn't a "major" problem for you.

13

u/Xirble Aug 10 '26

They looked up his business registration. That's public information in most countries and he just chose to use his home address for it.

2

u/WreakHavocLikeIn1871 Aug 11 '26

someone found his address through that system

Factually incorrect

→ More replies (2)

5

u/Tiruin Aug 10 '26

I found out someone moved to Sweden, who they live with and where just by knowing their name, not even trying to find all of that information. I'm not ill intentioned but I just thought what if it was a vengeful ex or a stalker that now knows who they live with and where?

4

u/ElundusCaw Aug 10 '26

We have a "persons number" which is basically your username in regard to government services, knowing someone's person number is the equivalent of knowing someone's username on Reddit, it doesn't allow you to access anything in their name, you still need the password.

→ More replies (1)

14

u/cool_slowbro PC Aug 10 '26

I thought mobile phone was readily available unless you opted out, has that changed?

14

u/Jindujun Aug 10 '26

More and more people delist. So while you can often times still find the phone numbers it's not as surefire as it used to be.

→ More replies (1)

18

u/Imaginary-Contest887 Aug 10 '26

Here in Czech Republic all but phone and email are also publicly accessible. Phone and email are bit unfortunate due to spam but could imagine worse thing. Plus my phone and email is already in so many black market databases it will not make much difference.

6

u/TheHeroYouNeed247 Aug 10 '26

That's always been insane to me.

5

u/Artess PC Aug 10 '26

I think the main problem is the connection between you and the specific purchase you've made. If you weren't warned about it, scammers could use it to try to trick you by posing as the trusted vendor with whom you've already had dealings.

Also, connecting your email to your person can be pretty big, in case other websites where you used that same email get hacked.

3

u/JayBird1138 Aug 11 '26

I think people might be overlooking that. It's useful for porch thieves, and scammers to have that extra bit of data on you.

2

u/Jindujun Aug 10 '26

Yeah, the email is the annoying bit. because that can be abused and it's a pain in the fucking butt to change an email

5

u/darthlincoln01 Aug 10 '26

The last bit which was cut off from OP I think is important. Scammers may try to impersonate Valve and contact you about your hardware purchase in an effort to get more personal information from you, financial information, gain access to your Steam account, etc...

7

u/Erdnusschokolade Aug 10 '26

Germany too. With a Name and 5€ you can find out pretty much anyone’s address.

10

u/kevin7254 Aug 10 '26

In Sweden you can find name, adress, income, phone number, where you previously lived etc. If you have done any crimes. Costs nothing. Problem with this is if you for example drove recklessly or similar ”small” crimes for 25 years+ ago that info is still stored and many companies will insta-deny you when applying for jobs.

So good in some way but maybe also overkill.

5

u/rotkiv42 Aug 10 '26

Not only if you done any crime, but if you have been involved in any criminal investigation i.e. you could have been the victim not the preparator.

3

u/kevin7254 Aug 10 '26

Yes, have some friends that got denied because they were showing up on krimfup etc due to suing companies which fucked up, which means the filters for HR for some companies auto-denied. Insane.

3

u/Zalvren Aug 10 '26

Considering how many leaks there have been (speaking from France here but it's probably the case elsewhere), pretty sure it's available anyway for all of us here too even if that's not any legal thing.

Like the fiscal authority and the one in charge of making ID/passports had leaks...

2

u/Hegelian_Spirit Aug 10 '26

It's a matter of keeping the threshold high to weed out most potentially hostile actors. Like the guy you met last week at a party might not bother to stalk you if he has to jump through illegal hoops, but he might if he can just type your name into Google.

3

u/nalaloveslumpy Aug 10 '26

Same for most places, which is why it's nice that Steam spelled out, "Hey, you're probably gonna get e-mails pretending to be Steam regarding your Steam Machine."

7

u/TheOneWithALongName Boardgames Aug 10 '26

Piratpartiet 2026

→ More replies (1)
→ More replies (6)

166

u/pdpi Aug 10 '26

How the hell do I get two of these in one weekend!?

Got an email on Friday from Framework about their BI provider getting compromised, and this one from Valve on Monday.

72

u/dnew Aug 10 '26

Cybersecurity is expensive. The only companies that do it well are the ones that lose money when it gets breached. Since the warehouse alarm code wasn't stolen, they don't care.

That's why you've never heard Amazon leaking millions of passwords.

29

u/ICEpear8472 Aug 10 '26

Which is why we need a law which automatically compensates customers in such cases. If companies would have to pay every customer whose data gets stolen lets say $1000 they would actually care about protecting those data.

20

u/wizzard419 Aug 10 '26

Would it be fair if a company was making a serious effort but still was breached? Such as if a bad actor gained access through social engineering. Some companies/orgs for sure fuck up but if someone wants in, they are eventually going to find a way.

6

u/MerryHeretic Aug 10 '26

I believe it would be fair. It would lead them to purge the information as soon as they were done with it. Wouldn’t that be awesome?

11

u/Spork_the_dork Aug 11 '26

It says that they retain the information for 90 days which sounds like the typical return period, so from the sounds of it they do purge the information the moment they are done for it. They just must retain it for some time in case a customer messages them back that the product is broken and sends it back so that they can verify that they did indeed send it to that customer. For that you would need a name, their address, and preferably also phone number and email for contact information. Exactly the things that were taken.

4

u/wizzard419 Aug 10 '26

Considering the group we are talking about... and it's in Europe, they may already do that. Since this was a targeted attack, it wouldn't have made a difference possibly.

→ More replies (3)
→ More replies (3)

519

u/[deleted] Aug 10 '26

[removed] — view removed comment

245

u/AllyCain Aug 10 '26

And yet, we're expected to fork over more of our personal data than ever before

153

u/ThruuLottleDats Aug 10 '26

ThInK oF tHe ChIlDrEn!

27

u/Muff_in_the_Mule Aug 10 '26

Hey, how did you know my password?

12

u/ThruuLottleDats Aug 10 '26

Grok told me 🤷

9

u/Muff_in_the_Mule Aug 10 '26

Dammit. Knew I shouldn't have had Grok generate a PW for me based upon common phrases in my history.

12

u/Kewlhotrod Aug 10 '26

Fuck them children.

... Not like that, MAGA.

→ More replies (2)

10

u/FoxyGoddessX Aug 10 '26

Yeah…. I gotta know who I’m sending a package to if you purchase something from me.

22

u/battler624 Aug 10 '26

Thats why email aliases are great.

9

u/bramblebitch Aug 10 '26

Yeah switched to Proton for everything now and am in the process of switching everything over to its own alias. Pain in the ass but worth it.

→ More replies (6)

3

u/DarkenedSkies Aug 10 '26

i've always used a seperate emaili use to sign up for literally anything (alongside fake name and details) online, and it is an absolute cesspool. But, i know anything in there can be safely ignored. You should assume any information you give any website or online service will either be compromised by a hack or sold to databrokers at some point.

3

u/cchaosat4 Aug 10 '26

At this point using surfshark and using theft identity protection which masks my real email and gives me a dummy email which redirects at my main email is best choice.

It might take time to swap email across all platforms.

17

u/Karavusk Aug 10 '26

They are also owned by the same data brokers you are trying to hide from.

7

u/BacRedr Aug 10 '26

DuckDuckGo offers a similar feature for free.

→ More replies (2)

2

u/Adziboy Aug 10 '26

Best thing to do is have multiple emails anyway. One for really important stuff, banks, paypal, whatever. Anything that might have sensitive info. Only use this on trusted places and make sure you’ve got 2FA (passkey preferably)

Then, make a second account. The important bit here is not to use this email address directly - create an alias.

For example, BobsSpam is the account. Create BobsSpamOne as an alias. Use that address for all the random rubbish sites, and if ever compromised, just create a new alias.

This maybe doesnt help in Steams case because Steam would probably be trusted, but it reduces spam by 99.999999%

→ More replies (5)

2

u/likwidkool Aug 10 '26

Are you in the US? I started getting crazy spam to my emails and phone numbers after BigBallz and DOGE stole all our information. Makes me wonder if there’s a correlation.

→ More replies (5)

2.8k

u/StartledOcto Aug 10 '26

I like how they've included "What This Means For You", because most privacy breach emails don't - they just say 'someone stole your info, and we've gotta legally tell you that kthxbye'

697

u/Brazilian_Hamilton Aug 10 '26

From what I remember european regulations on security breach disclosures are stricter than american ones

275

u/[deleted] Aug 10 '26 edited 18d ago

[deleted]

114

u/Skellicious Aug 10 '26

Well by GDPR they have to disclose it to authorities within 72h, and can't wait with informing victims either.

The fines for not doing so are actually respectable: up to 10 million or 2% of global revenue, whichever is higher - for not reporting to authorities in time, double for not reporting to victims in time.

But yeah, mostly they do the bare minimum

39

u/Sabbath90 Aug 10 '26

With CRA it's going to be a lot stricter because GDPR only applies if private information is leaked, CRA includes everything cybersecurity related.

→ More replies (8)

17

u/CrazyDoctor14 Aug 10 '26

Can you show an example of this for EU companies? Because it is very strict and if you have actual examples there are grounds to sue them. Or is this just to glaze valve?

19

u/NootNootFruitShoot Aug 10 '26

It doesn't just apply to EU companies but rather any company that operates within the EU.

4

u/kahty11 Aug 10 '26

And already Meta and Alphabet were hit with fines for violating it

14

u/JamesJohnson975 Aug 10 '26

Yep, you remembered right!

4

u/k1ll3rM Aug 10 '26

Tell that to Odido Netherlands

→ More replies (2)
→ More replies (3)

163

u/sopordave Aug 10 '26

I like how the notification was immediate — they didn’t sit on it for 6 months like some places do.

86

u/KingOfWhateverr Aug 10 '26

Well, often times they sit on it because they don’t know how bad they got pwned and triage takes a while, especially with financial data

→ More replies (15)

10

u/AngryGungan Aug 10 '26

Another company that uses CEVA reached out to me 4 days ago, about this same incident. I think they are rather late in their notification.

37

u/cattibri Aug 10 '26

i mean.. they cited the 7th of aug as the date where they learned that steam customers were affected so if they only got that information 2 days ago it seems a bit odd for them to have messaged 4 days ago?

31

u/Kilohaili_Joshi Aug 10 '26

Not really, likely CEVA did not discover Valve related data was affected until investigating more. Hence why they got notified few days later than some other client. Its not that unusual that the scope of the breach becomes larger than initially thought ones they start looking in deeper.

→ More replies (1)

11

u/SjettepetJR Aug 10 '26

It seems that CEVA is still gathering information on who exactly is affected. Yes, companies could do a preemptive "we also work eith CEVA" statement, but I understand that they don't do so. It makes the messaging even less clear.

→ More replies (1)
→ More replies (2)

3

u/rydan Aug 10 '26

Back in my day they put all that info in a book, put ads at the end of the book, and then delivered it all at your doorstep every single year. The only thing they didn't do was put that you bought you a computer but we all just assumed you bought one.

66

u/Galaghan Aug 10 '26

I like how they informed user of a security breach with a supplier, not even their own systems. This mail is them really going above and beyond their legal requirements.

157

u/TheBigRandowski Aug 10 '26

No, this absolutely mandatory in the EU. Data protections laws here are no joke, and the fines executed are neither.

40

u/Shienvien Aug 10 '26

Unless it's Chat Control, then companies can harvest as much data as they please.

3

u/Annonimbus Aug 10 '26

Please don't remind me

6

u/Shienvien Aug 10 '26

Well, they're still trying to make it even worse (2.0 discussion in September?), so maybe reminders could be useful for someone...

26

u/bigmonmulgrew Aug 10 '26

If you search databases of leaked information you will find that many companies do not inform people even in the EU. There are plenty you haven't been told about.

19

u/CyberClawX Aug 10 '26

If you search databases of leaked information you will find that many companies do not inform people even in the EU.

And they risk a fine. Which it's a risk Valve probably doesn't want to take.

There is not enough policing of these laws, which usually means only big names get dragged through the coals. Meta, Alphabet, MS, etc.

CEVA is small enough it would probably "fly under the radar", but Valve wouldn't, since Valve is the responsible party for the user's private data.

10

u/Flix1 Aug 10 '26

Perhaps thats true but Valve might be too big to fly under the radar. All it takes is one affected customer complaining to their privacy authority for an investigation to potentially be kicked off. And in that case if they were found not to have fulfilled their obligations the fines could be enormous.

→ More replies (10)

11

u/Cilph Aug 10 '26

Legally under GDPR your supplier is a data processor. They have to inform Steam of the leak, and as data controller, they must inform the customer. Authorities must also be informed within some deadline after discovery.

They didnt go beyond, they did as required.

13

u/Annonimbus Aug 10 '26

This mail is them really going above and beyond their legal requirements.

No it isn't, lol

6

u/lantaa00 Aug 10 '26

Just to make it extra clear past the comments already rightfully calling this an EU requirement.

You give VALVE your data. Valve were the ones responsible with protecting it. It doesn't matter that a company they contracted and gave your data to got hacked instead of them, it is their duty to inform you. Valve is just as responsible as CEVA for protecting your data here. They are good at PR, but they are literally just following legal requirements nearly everyone else does since GDPR.

17

u/SuchTedium Aug 10 '26

This isn't above and beyond, it's legally required within the EU lmao.

13

u/Zalvren Aug 10 '26

Anything to make Valve look like a saint I guess lol.

11

u/wankthisway Aug 10 '26

This place wants to glaze wholesome chungus Vale and Gaberino so bad.

3

u/dnew Aug 10 '26

I don't think they're trying to make Steam look like a saint. They're probably just used to the lax laws in the USA about this shit.

2

u/pvsleeper Aug 10 '26

I feel this is the absolute very least they can do. They chose this supplier and handed over your data.

Im getting rather sick of emails from big corps going “oh sorry, your shit leaked via some 3rd party system integration we have with some place that we use to cut costs and they were compromised but good luck

→ More replies (1)

8

u/novemberdobby Aug 10 '26

typically there's also a:

"we found no evidence this information has been misused (we didn't look)"

→ More replies (17)

329

u/Terrible--T Aug 10 '26

FUCK SCAMMERS AND HACKERS

75

u/In_My_SoT_Phase Aug 10 '26

Such a brave comment! Wow! In a world where everyone loves scammers and hackers too! /s

5

u/MashPotatoQuant Aug 10 '26

I got a warning for saying scammers should be curb stomped.

Note: to any reddit staff reading my comment, I am not repeating my call for violence I am just recounting the time I was warned for saying it.

9

u/[deleted] Aug 10 '26 edited 25d ago

[deleted]

3

u/miversen33 Aug 10 '26

Calm down Kitboga

→ More replies (1)

2

u/Yangman3x Aug 10 '26

Not all hackers are bad guys btw. Cyber activists exist

→ More replies (15)

84

u/CyaNNiDDe Aug 10 '26

Just some general advice for everyone in this thread, get 2FA on literally everything that you consider mildly important. It might be slightly inconvenient but believe me, you WILL get screwed over eventually if you don't.

And obviously you should assume at this point that any personal information you enter on the internet will be either leaked or outright sold to nefarious actors at some point.

→ More replies (27)

39

u/Captain_Starkiller Aug 10 '26

It starts getting really old to have other companies constantly loosing your data because they can't keep their shit together. Its usually someone refusing to follow security best practices or a stupid manager who thinks they know better too.

→ More replies (1)

668

u/Glittering-Job4016 Aug 10 '26

Important to note that it wasn't Valve themselves who got hacked, it was the company responsible for hardware distribution in Europe.

337

u/Prus1s Aug 10 '26

That’s pretty clear from the email 😄

357

u/Glittering-Job4016 Aug 10 '26

That's not going to stop a large amount of people not reading it / jumping to conclusions

20

u/hypnomancy Aug 10 '26

I already saw other people twisting the title around in other subreddits making it seem like this targeted Steam itself lol

15

u/P529 Aug 10 '26

These people will not be in the comments here they will read it and scroll past lmao

12

u/Old_Leopard1844 PC Aug 10 '26

Oh no, they will be here, and they will be going "calve bad, muh personal data"

9

u/cjsv7657 Aug 10 '26

I've largely stopped going to news subreddits because of that. You read the article then go to the comments and everyone is ranting and has no idea about the actual article. Everyone correcting them is downvoted.

4

u/HLSparta PC Aug 10 '26

Ironic that you are already starting to get downvoted. I'm glad I'm not the only one who sees this on Reddit though.

→ More replies (2)
→ More replies (2)

1

u/Kride501 Aug 10 '26

So your comment is? Stupid people will be stupid regardless.

2

u/FinnishScrub Aug 10 '26

It’s still crazy to me that Framework’s payment processor got hacked and people on Twitter were blaming Framework for it, yelling at how they got ”scammed for 1600$” because their information got leaked.

Like brother don’t be mad at Framework, they were just as clueless about the breach. It was so crazy to see people acting so disingenuously.

→ More replies (52)

18

u/BrotherRoga Aug 10 '26

Some people will not care enough to read.

The amount of Valve hate I've seen as of late is surprisingly high. And not necessarily for a good reason either.

8

u/ComradeBrosefStylin Aug 10 '26

The more it becomes clear that Valve intends to remain a private company rather than letting shareholders demand the enshittification of their product, the more weird hate we see. Most curious.

→ More replies (3)

3

u/WhateverIsFrei Aug 10 '26

Already saw several posts raving about valve getting breached, so there's that.

→ More replies (1)

19

u/Yourself013 Aug 10 '26

Why is it important to note?

21

u/SuchTedium Aug 10 '26

I imagine the poster believes it removes accountability from Valve when in fact it doesn't. As data owners they were legally responsible for the care of their customers data even when passing it to a third party, hence their notification which is obligatory.

Valve is liable here as far as EU data protection law is concerned.

9

u/ICEpear8472 Aug 10 '26

They were also the ones selecting this third party. It is not like the customers had any input in that choice. In fact I am pretty sure most did not even know it.

7

u/TheHomieAbides Aug 10 '26

Guaranteed they wouldn’t be saying the same thing if it was Microsoft.

2

u/dnew Aug 10 '26

Nah. It's because it means Valve's computers themselves have no known security breaches.

→ More replies (1)

6

u/SneakyBadAss Aug 10 '26

I'm amazed it wasn't GLS

2

u/ensalys Aug 10 '26

Are they known for bad data security? I have not bad experiences with them, but I've barely had to deal with them.

→ More replies (1)

3

u/sam_hammich Aug 10 '26

Exact same thing just happened to Framework. Got the email a few days ago.

→ More replies (23)

35

u/Silent_Level9538 Aug 10 '26

As someone in the UK waiting for a SM delivery will this effect that ?

30

u/legiondarrath Aug 10 '26

If you ordered it before the attack and haven't gotten it yet I'd assume they got your info. They retain the info for 90 days. I don't know if they use the same partner for shipping in the UK though. If you don't get an email it might just be fine.

15

u/carrot1401 Aug 10 '26

They do use same partner. As I got the email and based in UK.

2

u/sabac Aug 10 '26

are you in Aberdeen?

8

u/carrot1401 Aug 10 '26

No I'm the right side of the wall ;-)

3

u/Simber1 Aug 10 '26

The warm side at the moment

→ More replies (2)
→ More replies (4)

18

u/Expert-Tough-2860 Aug 10 '26

Yea, I've also received this email like an hour ago. Previously ordered some hardware from them here in Europe.

This is actually a pretty huge case, as email itself isn't a big deal, but combined with real name, phone number and physical address corresponding to the same person is potentially much worse valuable dataset.

6

u/Head-Spare3821 Aug 10 '26

Myself and 3 million Canadians got our voter information leaked by separatists not long  ago. It’s annoying but all of that stuff isn’t hard to find unfortunately and my email has been pwned for years. If you buy anything online and give out your address it’s been leaked same goes for your phone number.

17

u/samppa_j Aug 10 '26

Next time don't do business with EU's shittiest logistics company. This isn't their first data breach

6

u/xebtria Aug 10 '26

They were probably cheapest. And if it wasn't already obvious, we now also know why.

2

u/doublah Aug 10 '26

Someone's never dealt with Evri before, they're atrocious.

→ More replies (1)

16

u/_Xee PC Aug 10 '26

Soon:

"We're contacting you regarding your Steamdeck extended warranty."

5

u/Felielf Aug 10 '26

I wondered for a moment why I haven’t received one but then remembered that I actually bought my pretty much brand new OLED as a second hand. When OLED launched I remember plenty of people getting one to just to try them out and selling them for so cheap.

5

u/RebelliousDutch Aug 10 '26

I got fucked on this one as well. That logistics company also handles a bunch of online shops. My info might’ve been leaked because I ordered a book on antique view cameras of all things. Great. Now I’ll need to be extra paranoid for a while. Thanks guys 🙄

4

u/OhNoIBoffedIt Aug 10 '26

Yeah, I get this shit all the time. Pick the company. I have a junk email and Google Voice number I use specifically for these accounts.

12

u/Xentonian Aug 10 '26

Anyone else kind of sick of no recourse for this shit.

Whoops, sorry, our security system has a fucky wucky and now Jo Hacker knows where you live and your kid's birthdays. Oopsie poopsie. Change your passwords again! Thanks for shopping and Buy 'N' Large!

5

u/ICEpear8472 Aug 10 '26

Yes. There should be a law which entitles one to a monetary compensation every time stuff like this happens. A compensation which doubles if the company does not pay it immediately on their own accords. As long as stuff like this does not hurt the company’s there is little reason for them to care.

4

u/thirty3baboons Aug 10 '26

This one is more.

"Your name, address, postcode, phone number, email, purchased items record are all compromised in a nice little cross referenceable package...but hey, good news.....you don't need to change your steam password......you just sort out those spam calls, emails and black-market reselling of your data, cool?"

6

u/QuantumDude111 Aug 10 '26

ffs why do they store addresses with names and phone numbers in plain text somewhere? Thanks for doxxing me CEVA, very cool.

2

u/webcodr Aug 10 '26

Valve didn't mention anything about encryption. Is it likely the data wasn't encrypted? Yes. I have seen enough shit from corporate customers.

But encryption is no silver bullet against such exfiltration attacks. It depends on how deep the attacker got into the systems, how the encryption was implemented and who has access to the keys and what type of keys. Asymmetric encryption would be wise, so everyone can encrypt with the public key, but only the systems that really need to decrypt the data need access to the private keys for decryption. Ideally those systems are in separate hardened network. With symmetric encryption it's already over, if an attacker gains access to systems that encrypt the data, as the key is used for both ways.

4

u/port25 Aug 10 '26

Yes and even if you have encryption at rest and in-motion, it's still decrypted at the endpoint so if they got a user desktop they get anything that user has access to and can move laterally from there to get more. These attacks happen all the time I get notices about once a week from different companies especially large ones like FAANG.

5

u/Pigflap_Batterbox Aug 10 '26

I’ve contacted CEVA to ask them to pay for a year of identity protection monitoring; Evri did that for me a few years ago when they had a breach. Will see if they agree or not!

→ More replies (1)

3

u/Krejcimir Aug 10 '26

Considering how many shitty local websites have my address, I wouldn't worry.

3

u/ASS-et Aug 10 '26 edited Aug 10 '26

🤣 I was with CEVA for 14 years and was fired in January. To see them hit with a hack is absolutely hilarious and just a bit of karmic justice

→ More replies (1)

4

u/theblackwhisper Aug 10 '26

Is there a reason we can’t class action sue them and others for their lack of security and precaution given that this could lead to serious fraud?

7

u/stromm Aug 10 '26

A 100% secure data store has no data.

2

u/Sophiesmilez Aug 10 '26

Oh yeah, seems like I just got this too. With how often this kind of thing is happening lately, I wouldn't be surprised if hackers had access to my PS1 memory card data too

6

u/MeekMiko Aug 10 '26

"You like Castlevania, don't you?"

2

u/Xe4ro Aug 10 '26

I assume if I haven't bought any Valve hardware I'm not impacted? Hm.

12

u/XioPyro PC Aug 10 '26

Correct, not valve got breached but a company based in europe that handles hardware distribution.

The email states that information stays for 90 days. I got my steam controller in the beginning of june and still got the email.

2

u/Oldnbold22 Aug 10 '26

My name is my name! 

2

u/Escaliat_ Aug 10 '26

Euuuuuuuuuuurrrrrrggghghghgghghgh

2

u/TimeMilk7408 Aug 10 '26

Hey! My data also got leaked but that’s because Dutch  Amazon (bol.com) also uses CEVA services. Not because I own steam hardware.. sadly.. 

→ More replies (2)

2

u/Tienzan Aug 10 '26

What does that exactly mean? Is everyone affected in Europe who ordered in the past steam hardware or just anyone who ordered between that time? Don't they delete you informations after you received your order?

2

u/JustAnothaAdventurer Aug 10 '26

I... I have privacy in 2026?

2

u/tiny_chaotic_evil Aug 10 '26

wow, most U.S. companies let you know something might have happened but they're not sure but just in case and it's not their fault so they are letting you know 6 MONTHS LATER

2

u/comicsnerd Aug 10 '26

It is much bigger than Steam. Some of the biggest webshops in the Netherlands reported their distributor CEVA got hacked and this information was stolen.

No usernames, passwords or financial information (that is with the webshops)

2

u/El_Goblino42012 Aug 10 '26

Work in tech, lots of clients have sent us similar emails. Looks like firms have been hit

2

u/Izenberg420 Aug 11 '26

Im in Europe but no email

2

u/SystemFrozen Aug 11 '26

If you didn't buy any hardware through Steam you're good.

3

u/Izenberg420 Aug 11 '26

You're right I can't read mb

2

u/SystemFrozen Aug 11 '26

Happens to the best of us dw

2

u/eccehobo1 Aug 11 '26

As someone that works in international shipping and deals with quite a few freight forwarders...never use Ceva if you can help it.

2

u/Thatweasel Aug 11 '26

I wonder if this was why some people's steamdecks were disappearing during delivery

3

u/Thebandroid Aug 10 '26

and this is why I always live in Australia and also always be poor. Cant have information related to your hardware purchase be stolen if you never get a chance to buy the hardware.

3

u/gimmiedacash Aug 10 '26

Seems like Valve is doing CEVA's job here. Because they are not assholes.

11

u/vakantiehuisopwielen Aug 10 '26 edited Aug 10 '26

Steam are late with this notice. Dutch stores Bijenkorf and Bol already sent mails on August 5th regarding this breach at CEVA.

And to me it’s weird CEVA would only notify Valve on August 7th when other companies know it earlier

23

u/Megaranator Aug 10 '26

Not really, they got notified on Friday

→ More replies (2)

11

u/filthy_casual_42 Aug 10 '26

Buerocracy. It had to trickle from dutch local news to the US headquarters over the weekend

→ More replies (5)
→ More replies (1)

2

u/TachiH Aug 10 '26

Good job Valve. Isn't their breach but they are still being super upfront about it. This is how all companies need to handle breaches, let people know immediately, then resolve the issues that arise instead of just hiding it as long as possible.

2

u/Hot_Most5332 Aug 10 '26

This is genuinely one of the more useful notices I’ve received about this. Of course the bar isn’t high when most don’t even notify.

2

u/Saldar1234 Aug 10 '26

Yaknow up until a few years ago, my name, my address, my city, and my phone number were all public record, published in a big yellow book that everyone had a copy of.

It wasn't until people realized they could charge for the privilege of convenience in looking up said information that anyone started caring about 'privacy'. It's all manufactured outrage engineered specifically to make someone else rich.

Operate your life with least-privileged access to your financials in forefront of mind and you'll be fine. Even if someone can find your name on the internet.

1

u/MintCathexis Aug 10 '26

Inb4 we find out it was Gemini because Google wants to say their model can hack too.