this post was submitted on 13 Aug 2026
81 points (96.6% liked)

Technology

87146 readers
4155 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
top 7 comments
sorted by: hot top controversial new old
[–] NaibofTabr@infosec.pub 43 points 1 day ago* (last edited 1 day ago)

Valve shares delivery-related information with CEVA so that it can ship Steam hardware in Europe, and it appears that this personal data is what was stolen. This personally identifiable information (PII) may include your name, address, country, phone number, email address, and the details of the products you ordered. CEVA stores customer data for up to 90 days after an order is assigned to them, which means that the data for lots of customers may have been leaked. Fortunately, payment information, Steam account details, authentication codes, and more are not stored at CEVA.

The leak was not from Valve but from the shipping company used to distribute their hardware in Europe. Your Steam account details are not leaked, but any information related to shipping probably is.

Following this breach and the subsequent exfiltration of data, Valve has asked customers to be wary of contact attempts from fraudulent entities who have taken hold of your leaked information and may use it to prove that they are genuine. Customers do not need to change their passwords, but they definitely should not share their account details with any person identifying them as a courier service for your hardware.

[–] myrmidex@belgae.social 14 points 21 hours ago (1 children)

It was refreshing to have a company publicly admit the breach, and not by press release but through direct email to their customers.

[–] LilBobbyTables@lemmy.today 6 points 17 hours ago (1 children)

There are legal frameworks around reporting of data breaches in most countries. They didn’t do this out of the goodness of their hearts.

[–] myrmidex@belgae.social 5 points 16 hours ago

Still, the other companies couldn't be bothered. Hell, most of the cities and towns in Belgium that got hacked felt no urgency to inform their citizens, so not sure how stringent those frameworks are...

[–] cattywampas@lemmy.world 15 points 1 day ago

At this point data breach emails are as regular as spam.

[–] bigtuffal@dice.camp 3 points 1 day ago (1 children)
[–] tal@lemmy.today 1 points 20 hours ago

It sounds like it's other countries in Europe as well.

https://old.reddit.com/r/gaming/comments/1vkgf1k/valve_notifying_hardware_customers_about_a/

They do use same partner. As I got the email and based in UK.