Valve emailed about a cyberattack against their shipping partner CEVA Logistics in Europe
Just got that E-Mail from Valve...
https://www.gamingonlinux.com/2026/08/valve-emailed-about-a-cyberattack-against-their-shipping-partner-ceva-logistics-in-europe/Open linkView original on feddit.org
8 replies
Got the email too. Oh well, guess my data got leaked again. Seems almost impossible to avoid these days if you ever want to buy something on the internet. At least it didn't include my passport number this time, unlike when Interrail was hacked...
I have to say, though, that I don't really get why Valve's shipping partner needed to retain my data for months after shipping out my products.
Most likely due to GDPR requirements. Depending on the type of data, companies are legally required to retain some or all of it for anywhere between 3 and 12 months, if I remember correctly.
You know, in case you ever turn your Steam Deck into a bomb - they'll be able to track it to you. Think twice.
This sounds pretty much like the opposite of what the GDPR aims for.
IANAL, but as I understand Article 5(1)(e), shipping companies need to give good reasons why they would be storing data after they have delivered the package:
My best guess is for handling of complaints. Like, people receive the package, but only open it some time later, just to realize that the contents have been damaged during transport.
Based on nothing at all I'm going to assert that Epic's CEO Tim Sweeney is directly responsible for this attack.
I got this email for an entirely different package, it's not just Steam hardware. Kinda pleased that I'm paranoid enough to give less information than asked. If I'm in the data they pulled, some hackers now know my address, last name, and that I buy parts for shavers.
Luckily I got mine sent to my work address. Still annoying though.
Be vigilant everyone
Not a huge deal it sounds like tbh
Got an email too :/