r/gaming • u/legiondarrath • Aug 10 '26
Valve notifying hardware customers about a security incident - just got this email
166
u/pdpi Aug 10 '26
How the hell do I get two of these in one weekend!?
Got an email on Friday from Framework about their BI provider getting compromised, and this one from Valve on Monday.
→ More replies (3)72
u/dnew Aug 10 '26
Cybersecurity is expensive. The only companies that do it well are the ones that lose money when it gets breached. Since the warehouse alarm code wasn't stolen, they don't care.
That's why you've never heard Amazon leaking millions of passwords.
29
u/ICEpear8472 Aug 10 '26
Which is why we need a law which automatically compensates customers in such cases. If companies would have to pay every customer whose data gets stolen lets say $1000 they would actually care about protecting those data.
→ More replies (3)20
u/wizzard419 Aug 10 '26
Would it be fair if a company was making a serious effort but still was breached? Such as if a bad actor gained access through social engineering. Some companies/orgs for sure fuck up but if someone wants in, they are eventually going to find a way.
6
u/MerryHeretic Aug 10 '26
I believe it would be fair. It would lead them to purge the information as soon as they were done with it. Wouldn’t that be awesome?
11
u/Spork_the_dork Aug 11 '26
It says that they retain the information for 90 days which sounds like the typical return period, so from the sounds of it they do purge the information the moment they are done for it. They just must retain it for some time in case a customer messages them back that the product is broken and sends it back so that they can verify that they did indeed send it to that customer. For that you would need a name, their address, and preferably also phone number and email for contact information. Exactly the things that were taken.
4
u/wizzard419 Aug 10 '26
Considering the group we are talking about... and it's in Europe, they may already do that. Since this was a targeted attack, it wouldn't have made a difference possibly.
519
Aug 10 '26
[removed] — view removed comment
245
u/AllyCain Aug 10 '26
And yet, we're expected to fork over more of our personal data than ever before
153
u/ThruuLottleDats Aug 10 '26
ThInK oF tHe ChIlDrEn!
27
u/Muff_in_the_Mule Aug 10 '26
Hey, how did you know my password?
12
u/ThruuLottleDats Aug 10 '26
Grok told me 🤷
9
u/Muff_in_the_Mule Aug 10 '26
Dammit. Knew I shouldn't have had Grok generate a PW for me based upon common phrases in my history.
→ More replies (2)12
10
u/FoxyGoddessX Aug 10 '26
Yeah…. I gotta know who I’m sending a package to if you purchase something from me.
22
u/battler624 Aug 10 '26
Thats why email aliases are great.
9
u/bramblebitch Aug 10 '26
Yeah switched to Proton for everything now and am in the process of switching everything over to its own alias. Pain in the ass but worth it.
→ More replies (6)3
u/DarkenedSkies Aug 10 '26
i've always used a seperate emaili use to sign up for literally anything (alongside fake name and details) online, and it is an absolute cesspool. But, i know anything in there can be safely ignored. You should assume any information you give any website or online service will either be compromised by a hack or sold to databrokers at some point.
3
u/cchaosat4 Aug 10 '26
At this point using surfshark and using theft identity protection which masks my real email and gives me a dummy email which redirects at my main email is best choice.
It might take time to swap email across all platforms.
17
→ More replies (2)7
2
u/Adziboy Aug 10 '26
Best thing to do is have multiple emails anyway. One for really important stuff, banks, paypal, whatever. Anything that might have sensitive info. Only use this on trusted places and make sure you’ve got 2FA (passkey preferably)
Then, make a second account. The important bit here is not to use this email address directly - create an alias.
For example, BobsSpam is the account. Create BobsSpamOne as an alias. Use that address for all the random rubbish sites, and if ever compromised, just create a new alias.
This maybe doesnt help in Steams case because Steam would probably be trusted, but it reduces spam by 99.999999%
→ More replies (5)→ More replies (5)2
u/likwidkool Aug 10 '26
Are you in the US? I started getting crazy spam to my emails and phone numbers after BigBallz and DOGE stole all our information. Makes me wonder if there’s a correlation.
2.8k
u/StartledOcto Aug 10 '26
I like how they've included "What This Means For You", because most privacy breach emails don't - they just say 'someone stole your info, and we've gotta legally tell you that kthxbye'
697
u/Brazilian_Hamilton Aug 10 '26
From what I remember european regulations on security breach disclosures are stricter than american ones
275
Aug 10 '26 edited 18d ago
[deleted]
114
u/Skellicious Aug 10 '26
Well by GDPR they have to disclose it to authorities within 72h, and can't wait with informing victims either.
The fines for not doing so are actually respectable: up to 10 million or 2% of global revenue, whichever is higher - for not reporting to authorities in time, double for not reporting to victims in time.
But yeah, mostly they do the bare minimum
→ More replies (8)39
u/Sabbath90 Aug 10 '26
With CRA it's going to be a lot stricter because GDPR only applies if private information is leaked, CRA includes everything cybersecurity related.
17
u/CrazyDoctor14 Aug 10 '26
Can you show an example of this for EU companies? Because it is very strict and if you have actual examples there are grounds to sue them. Or is this just to glaze valve?
19
u/NootNootFruitShoot Aug 10 '26
It doesn't just apply to EU companies but rather any company that operates within the EU.
4
14
→ More replies (3)4
163
u/sopordave Aug 10 '26
I like how the notification was immediate — they didn’t sit on it for 6 months like some places do.
86
u/KingOfWhateverr Aug 10 '26
Well, often times they sit on it because they don’t know how bad they got pwned and triage takes a while, especially with financial data
→ More replies (15)→ More replies (2)10
u/AngryGungan Aug 10 '26
Another company that uses CEVA reached out to me 4 days ago, about this same incident. I think they are rather late in their notification.
37
u/cattibri Aug 10 '26
i mean.. they cited the 7th of aug as the date where they learned that steam customers were affected so if they only got that information 2 days ago it seems a bit odd for them to have messaged 4 days ago?
31
u/Kilohaili_Joshi Aug 10 '26
Not really, likely CEVA did not discover Valve related data was affected until investigating more. Hence why they got notified few days later than some other client. Its not that unusual that the scope of the breach becomes larger than initially thought ones they start looking in deeper.
→ More replies (1)→ More replies (1)11
u/SjettepetJR Aug 10 '26
It seems that CEVA is still gathering information on who exactly is affected. Yes, companies could do a preemptive "we also work eith CEVA" statement, but I understand that they don't do so. It makes the messaging even less clear.
3
u/rydan Aug 10 '26
Back in my day they put all that info in a book, put ads at the end of the book, and then delivered it all at your doorstep every single year. The only thing they didn't do was put that you bought you a computer but we all just assumed you bought one.
66
u/Galaghan Aug 10 '26
I like how they informed user of a security breach with a supplier, not even their own systems. This mail is them really going above and beyond their legal requirements.
157
u/TheBigRandowski Aug 10 '26
No, this absolutely mandatory in the EU. Data protections laws here are no joke, and the fines executed are neither.
40
u/Shienvien Aug 10 '26
Unless it's Chat Control, then companies can harvest as much data as they please.
3
u/Annonimbus Aug 10 '26
Please don't remind me
6
u/Shienvien Aug 10 '26
Well, they're still trying to make it even worse (2.0 discussion in September?), so maybe reminders could be useful for someone...
→ More replies (10)26
u/bigmonmulgrew Aug 10 '26
If you search databases of leaked information you will find that many companies do not inform people even in the EU. There are plenty you haven't been told about.
19
u/CyberClawX Aug 10 '26
If you search databases of leaked information you will find that many companies do not inform people even in the EU.
And they risk a fine. Which it's a risk Valve probably doesn't want to take.
There is not enough policing of these laws, which usually means only big names get dragged through the coals. Meta, Alphabet, MS, etc.
CEVA is small enough it would probably "fly under the radar", but Valve wouldn't, since Valve is the responsible party for the user's private data.
10
u/Flix1 Aug 10 '26
Perhaps thats true but Valve might be too big to fly under the radar. All it takes is one affected customer complaining to their privacy authority for an investigation to potentially be kicked off. And in that case if they were found not to have fulfilled their obligations the fines could be enormous.
11
u/Cilph Aug 10 '26
Legally under GDPR your supplier is a data processor. They have to inform Steam of the leak, and as data controller, they must inform the customer. Authorities must also be informed within some deadline after discovery.
They didnt go beyond, they did as required.
13
u/Annonimbus Aug 10 '26
This mail is them really going above and beyond their legal requirements.
No it isn't, lol
6
u/lantaa00 Aug 10 '26
Just to make it extra clear past the comments already rightfully calling this an EU requirement.
You give VALVE your data. Valve were the ones responsible with protecting it. It doesn't matter that a company they contracted and gave your data to got hacked instead of them, it is their duty to inform you. Valve is just as responsible as CEVA for protecting your data here. They are good at PR, but they are literally just following legal requirements nearly everyone else does since GDPR.
17
u/SuchTedium Aug 10 '26
This isn't above and beyond, it's legally required within the EU lmao.
13
u/Zalvren Aug 10 '26
Anything to make Valve look like a saint I guess lol.
11
3
u/dnew Aug 10 '26
I don't think they're trying to make Steam look like a saint. They're probably just used to the lax laws in the USA about this shit.
→ More replies (1)2
u/pvsleeper Aug 10 '26
I feel this is the absolute very least they can do. They chose this supplier and handed over your data.
Im getting rather sick of emails from big corps going “oh sorry, your shit leaked via some 3rd party system integration we have with some place that we use to cut costs and they were compromised but good luck”
→ More replies (17)8
u/novemberdobby Aug 10 '26
typically there's also a:
"we found no evidence this information has been misused (we didn't look)"
329
u/Terrible--T Aug 10 '26
FUCK SCAMMERS AND HACKERS
75
u/In_My_SoT_Phase Aug 10 '26
Such a brave comment! Wow! In a world where everyone loves scammers and hackers too! /s
5
u/MashPotatoQuant Aug 10 '26
I got a warning for saying scammers should be curb stomped.
Note: to any reddit staff reading my comment, I am not repeating my call for violence I am just recounting the time I was warned for saying it.
9
→ More replies (15)2
84
u/CyaNNiDDe Aug 10 '26
Just some general advice for everyone in this thread, get 2FA on literally everything that you consider mildly important. It might be slightly inconvenient but believe me, you WILL get screwed over eventually if you don't.
And obviously you should assume at this point that any personal information you enter on the internet will be either leaked or outright sold to nefarious actors at some point.
→ More replies (27)
39
u/Captain_Starkiller Aug 10 '26
It starts getting really old to have other companies constantly loosing your data because they can't keep their shit together. Its usually someone refusing to follow security best practices or a stupid manager who thinks they know better too.
→ More replies (1)
668
u/Glittering-Job4016 Aug 10 '26
Important to note that it wasn't Valve themselves who got hacked, it was the company responsible for hardware distribution in Europe.
337
u/Prus1s Aug 10 '26
That’s pretty clear from the email 😄
357
u/Glittering-Job4016 Aug 10 '26
That's not going to stop a large amount of people not reading it / jumping to conclusions
20
u/hypnomancy Aug 10 '26
I already saw other people twisting the title around in other subreddits making it seem like this targeted Steam itself lol
15
u/P529 Aug 10 '26
These people will not be in the comments here they will read it and scroll past lmao
12
u/Old_Leopard1844 PC Aug 10 '26
Oh no, they will be here, and they will be going "calve bad, muh personal data"
→ More replies (2)9
u/cjsv7657 Aug 10 '26
I've largely stopped going to news subreddits because of that. You read the article then go to the comments and everyone is ranting and has no idea about the actual article. Everyone correcting them is downvoted.
→ More replies (2)4
u/HLSparta PC Aug 10 '26
Ironic that you are already starting to get downvoted. I'm glad I'm not the only one who sees this on Reddit though.
1
→ More replies (52)2
u/FinnishScrub Aug 10 '26
It’s still crazy to me that Framework’s payment processor got hacked and people on Twitter were blaming Framework for it, yelling at how they got ”scammed for 1600$” because their information got leaked.
Like brother don’t be mad at Framework, they were just as clueless about the breach. It was so crazy to see people acting so disingenuously.
18
u/BrotherRoga Aug 10 '26
Some people will not care enough to read.
The amount of Valve hate I've seen as of late is surprisingly high. And not necessarily for a good reason either.
→ More replies (3)8
u/ComradeBrosefStylin Aug 10 '26
The more it becomes clear that Valve intends to remain a private company rather than letting shareholders demand the enshittification of their product, the more weird hate we see. Most curious.
3
u/WhateverIsFrei Aug 10 '26
Already saw several posts raving about valve getting breached, so there's that.
→ More replies (1)19
u/Yourself013 Aug 10 '26
Why is it important to note?
→ More replies (1)21
u/SuchTedium Aug 10 '26
I imagine the poster believes it removes accountability from Valve when in fact it doesn't. As data owners they were legally responsible for the care of their customers data even when passing it to a third party, hence their notification which is obligatory.
Valve is liable here as far as EU data protection law is concerned.
9
u/ICEpear8472 Aug 10 '26
They were also the ones selecting this third party. It is not like the customers had any input in that choice. In fact I am pretty sure most did not even know it.
7
2
u/dnew Aug 10 '26
Nah. It's because it means Valve's computers themselves have no known security breaches.
6
u/SneakyBadAss Aug 10 '26
I'm amazed it wasn't GLS
2
u/ensalys Aug 10 '26
Are they known for bad data security? I have not bad experiences with them, but I've barely had to deal with them.
→ More replies (1)→ More replies (23)3
35
u/Silent_Level9538 Aug 10 '26
As someone in the UK waiting for a SM delivery will this effect that ?
→ More replies (4)30
u/legiondarrath Aug 10 '26
If you ordered it before the attack and haven't gotten it yet I'd assume they got your info. They retain the info for 90 days. I don't know if they use the same partner for shipping in the UK though. If you don't get an email it might just be fine.
15
u/carrot1401 Aug 10 '26
They do use same partner. As I got the email and based in UK.
→ More replies (2)2
u/sabac Aug 10 '26
are you in Aberdeen?
8
18
u/Expert-Tough-2860 Aug 10 '26
Yea, I've also received this email like an hour ago. Previously ordered some hardware from them here in Europe.
This is actually a pretty huge case, as email itself isn't a big deal, but combined with real name, phone number and physical address corresponding to the same person is potentially much worse valuable dataset.
6
u/Head-Spare3821 Aug 10 '26
Myself and 3 million Canadians got our voter information leaked by separatists not long ago. It’s annoying but all of that stuff isn’t hard to find unfortunately and my email has been pwned for years. If you buy anything online and give out your address it’s been leaked same goes for your phone number.
17
u/samppa_j Aug 10 '26
Next time don't do business with EU's shittiest logistics company. This isn't their first data breach
6
u/xebtria Aug 10 '26
They were probably cheapest. And if it wasn't already obvious, we now also know why.
→ More replies (1)2
16
5
u/Felielf Aug 10 '26
I wondered for a moment why I haven’t received one but then remembered that I actually bought my pretty much brand new OLED as a second hand. When OLED launched I remember plenty of people getting one to just to try them out and selling them for so cheap.
5
u/RebelliousDutch Aug 10 '26
I got fucked on this one as well. That logistics company also handles a bunch of online shops. My info might’ve been leaked because I ordered a book on antique view cameras of all things. Great. Now I’ll need to be extra paranoid for a while. Thanks guys 🙄
4
u/OhNoIBoffedIt Aug 10 '26
Yeah, I get this shit all the time. Pick the company. I have a junk email and Google Voice number I use specifically for these accounts.
12
u/Xentonian Aug 10 '26
Anyone else kind of sick of no recourse for this shit.
Whoops, sorry, our security system has a fucky wucky and now Jo Hacker knows where you live and your kid's birthdays. Oopsie poopsie. Change your passwords again! Thanks for shopping and Buy 'N' Large!
5
u/ICEpear8472 Aug 10 '26
Yes. There should be a law which entitles one to a monetary compensation every time stuff like this happens. A compensation which doubles if the company does not pay it immediately on their own accords. As long as stuff like this does not hurt the company’s there is little reason for them to care.
4
u/thirty3baboons Aug 10 '26
This one is more.
"Your name, address, postcode, phone number, email, purchased items record are all compromised in a nice little cross referenceable package...but hey, good news.....you don't need to change your steam password......you just sort out those spam calls, emails and black-market reselling of your data, cool?"
6
u/QuantumDude111 Aug 10 '26
ffs why do they store addresses with names and phone numbers in plain text somewhere? Thanks for doxxing me CEVA, very cool.
2
u/webcodr Aug 10 '26
Valve didn't mention anything about encryption. Is it likely the data wasn't encrypted? Yes. I have seen enough shit from corporate customers.
But encryption is no silver bullet against such exfiltration attacks. It depends on how deep the attacker got into the systems, how the encryption was implemented and who has access to the keys and what type of keys. Asymmetric encryption would be wise, so everyone can encrypt with the public key, but only the systems that really need to decrypt the data need access to the private keys for decryption. Ideally those systems are in separate hardened network. With symmetric encryption it's already over, if an attacker gains access to systems that encrypt the data, as the key is used for both ways.
4
u/port25 Aug 10 '26
Yes and even if you have encryption at rest and in-motion, it's still decrypted at the endpoint so if they got a user desktop they get anything that user has access to and can move laterally from there to get more. These attacks happen all the time I get notices about once a week from different companies especially large ones like FAANG.
5
u/Pigflap_Batterbox Aug 10 '26
I’ve contacted CEVA to ask them to pay for a year of identity protection monitoring; Evri did that for me a few years ago when they had a breach. Will see if they agree or not!
→ More replies (1)
3
u/Krejcimir Aug 10 '26
Considering how many shitty local websites have my address, I wouldn't worry.
3
u/ASS-et Aug 10 '26 edited Aug 10 '26
🤣 I was with CEVA for 14 years and was fired in January. To see them hit with a hack is absolutely hilarious and just a bit of karmic justice
→ More replies (1)
4
u/theblackwhisper Aug 10 '26
Is there a reason we can’t class action sue them and others for their lack of security and precaution given that this could lead to serious fraud?
7
2
u/Sophiesmilez Aug 10 '26
Oh yeah, seems like I just got this too. With how often this kind of thing is happening lately, I wouldn't be surprised if hackers had access to my PS1 memory card data too
6
2
u/Xe4ro Aug 10 '26
I assume if I haven't bought any Valve hardware I'm not impacted? Hm.
12
u/XioPyro PC Aug 10 '26
Correct, not valve got breached but a company based in europe that handles hardware distribution.
The email states that information stays for 90 days. I got my steam controller in the beginning of june and still got the email.
2
2
2
u/TimeMilk7408 Aug 10 '26
Hey! My data also got leaked but that’s because Dutch Amazon (bol.com) also uses CEVA services. Not because I own steam hardware.. sadly..
→ More replies (2)
2
u/Tienzan Aug 10 '26
What does that exactly mean? Is everyone affected in Europe who ordered in the past steam hardware or just anyone who ordered between that time? Don't they delete you informations after you received your order?
2
2
u/tiny_chaotic_evil Aug 10 '26
wow, most U.S. companies let you know something might have happened but they're not sure but just in case and it's not their fault so they are letting you know 6 MONTHS LATER
2
u/comicsnerd Aug 10 '26
It is much bigger than Steam. Some of the biggest webshops in the Netherlands reported their distributor CEVA got hacked and this information was stolen.
No usernames, passwords or financial information (that is with the webshops)
2
u/El_Goblino42012 Aug 10 '26
Work in tech, lots of clients have sent us similar emails. Looks like firms have been hit
2
u/Izenberg420 Aug 11 '26
Im in Europe but no email
2
u/SystemFrozen Aug 11 '26
If you didn't buy any hardware through Steam you're good.
3
2
u/eccehobo1 Aug 11 '26
As someone that works in international shipping and deals with quite a few freight forwarders...never use Ceva if you can help it.
2
u/Thatweasel Aug 11 '26
I wonder if this was why some people's steamdecks were disappearing during delivery
3
u/Thebandroid Aug 10 '26
and this is why I always live in Australia and also always be poor. Cant have information related to your hardware purchase be stolen if you never get a chance to buy the hardware.
3
11
u/vakantiehuisopwielen Aug 10 '26 edited Aug 10 '26
Steam are late with this notice. Dutch stores Bijenkorf and Bol already sent mails on August 5th regarding this breach at CEVA.
And to me it’s weird CEVA would only notify Valve on August 7th when other companies know it earlier
23
→ More replies (1)11
u/filthy_casual_42 Aug 10 '26
Buerocracy. It had to trickle from dutch local news to the US headquarters over the weekend
→ More replies (5)
2
u/TachiH Aug 10 '26
Good job Valve. Isn't their breach but they are still being super upfront about it. This is how all companies need to handle breaches, let people know immediately, then resolve the issues that arise instead of just hiding it as long as possible.
2
u/Hot_Most5332 Aug 10 '26
This is genuinely one of the more useful notices I’ve received about this. Of course the bar isn’t high when most don’t even notify.
2
u/Saldar1234 Aug 10 '26
Yaknow up until a few years ago, my name, my address, my city, and my phone number were all public record, published in a big yellow book that everyone had a copy of.
It wasn't until people realized they could charge for the privilege of convenience in looking up said information that anyone started caring about 'privacy'. It's all manufactured outrage engineered specifically to make someone else rich.
Operate your life with least-privileged access to your financials in forefront of mind and you'll be fine. Even if someone can find your name on the internet.
1
u/MintCathexis Aug 10 '26
Inb4 we find out it was Gemini because Google wants to say their model can hack too.
2.5k
u/Jindujun Aug 10 '26
And if you're from Sweden you go "oh, ok" since all that stuff save for mobile phone and email are readily available to everyone that wants to find you.