Data Breach
Ongoing coverage on Data Breach.
Latest coverage
Gamescom Asia x Thailand Game Show announces exhibitor lineup for 2026
Gamescom Asia x Thailand Game Show has revealed its exhibitor lineup for 2026, featuring major companies like Capcom, Bandai Namco, and The Pokémon Company, alongside Nintendo and PlayStation represented by partners. The event will also host over 70 speakers, including John Romero, who will receive a lifetime achievement award. Separately, a Valve bug has led to the accidental leak of achievement data for numerous unreleased and unannounced Steam games, including Fable, Persona 6, and Kingdom Hearts 4.
Valve experienced a massive 12TB leak
Valve has experienced a massive 12TB data leak, dubbed the 'teraleak', containing files from Steam titles between 2003 and 2013. The leak includes content for games like Team Fortress 2, Dota 2, Left 4 Dead, and early builds of Portal 2, as well as cancelled projects like F-STOP and an unused weapon from Half-Life 2: Episode 3. The data was reportedly accessed from a publicly accessible endpoint rather than through a hack, with Valve yet to issue an official statement.
Digital scans of more than 153 million driver's licenses leaked to the dark web
Over 153 million driver's licenses have been leaked to the dark web, potentially originating from an ID verification service in Louisiana. The FBI has launched an investigation into the massive data breach.
Report: 13TB of Steam data leaked after users access 'publicly accessible endpoint'
A significant data leak, dubbed 'Steam2 leak,' has reportedly exposed 13TB of data from Valve's Steam platform, primarily containing files uploaded between 2003 and 2013. The leaked data includes early versions and assets of Valve games like Left 4 Dead 2 and Portal 2, as well as beta builds of third-party titles such as Dragon Age: Origins and Batman: Arkham Asylum. The information was allegedly accessed via a publicly accessible endpoint, raising security concerns for Valve and other exposed companies.
The Pokémon Company Cancels 30th Anniversary Card Orders Following 'Cyber Incident,' Warns of Customer Data Breach
The Pokémon Company has cancelled orders for its 30th Anniversary Cards due to a cyber incident that may have exposed customer data. The company is warning customers about a potential data breach.
Pokémon Center in the UK and Germany hit with the same data breach suffered by Valve's Steam hardware
The Pokémon Center's official stores in the UK and Germany have been affected by a data breach originating from their shipping partner, CEVA Logistics. This breach, which also impacted Valve's Steam hardware customers, may have exposed customer names, addresses, phone numbers, email addresses, and order details. Payment information was not compromised, but some affected orders have been cancelled, leading to potential delays and the unavailability of limited-edition items.
13,689 Trezor Customers Caught Up in Data Leak at Third-Party Shipping Partner
A data breach at Trezor's third-party shipping partner, ShipMonk, has exposed the personal information of 13,689 customers, including names, addresses, and phone numbers. While Trezor's own infrastructure remains secure, the leaked data increases the risk of targeted phishing attacks. The company plans to introduce an 'Anonymous Delivery' feature by the end of 2026 to enhance customer privacy.
Valve confirms Steam hardware buyers' data exposed in CEVA Logistics cyberattack
Valve has informed European customers that their personal data may have been exposed due to a cyberattack on its shipping partner, CEVA Logistics, between July 29 and August 1. The compromised information includes names, addresses, and order details for Steam hardware like the Steam Deck, but not payment information or passwords. Customers are advised to be wary of potential phishing attempts.
Steam user data 'may have been compromised' by a cyberattack targeting Valve's European shipping partner
Valve has informed European customers who purchased Steam hardware that their personal information may have been compromised due to a cyberattack on its shipping partner, CEVA Logistics. The breach, which occurred between July 29 and August 1, 2026, could have exposed names, addresses, phone numbers, email addresses, and order details. Valve states that payment information and unrelated Steam account data should remain secure.
Steam's shipping company has been hacked, but Valve says that your details are safe
Valve has confirmed a data breach affecting its shipping partner, CEVA Logistics, which handles Steam hardware distribution in Europe. While payment details and passwords remain secure, hackers may have accessed customer postal addresses, phone numbers, and email addresses. Valve is notifying affected customers and data protection authorities, advising vigilance against potential phishing attempts.
"Expect fake messages" - Valve's EU shipping partner suffers a data breach, so if you bought a Steam Machine or Steam Controller, you may need to be on guard
Valve has warned European customers to expect fake messages following a data breach at its shipping partner, CEVA Logistics. While payment details were not compromised, customer names, addresses, phone numbers, and email addresses were likely accessed. Customers are advised to treat any suspicious communications regarding deliveries or fees as fraudulent.
Steam hardware hit by cyberattack as Valve warns against 'fake messages'
Valve has warned Steam customers in Europe who purchased hardware that their data was likely compromised due to a cyberattack on shipping partner CEVA Logistics between July 29 and August 1, 2026. The compromised information includes names, addresses, country, phone numbers, email addresses, and product order details, but not passwords or payment information. Valve is urging customers to be vigilant against potential phishing attempts that may quote their personal details.
"Expect fake messages": A load of Steam user personal info has been stolen thanks to a cyberattack on one of Valve's partners, claims report
A cyberattack on CEVA Logistics, a shipping partner for Valve's Steam hardware in Europe, has potentially compromised the personal information of customers. The breach, which occurred between July 29 and August 1, 2026, may have exposed names, phone numbers, emails, and postal addresses, though payment information and passwords were not accessed. Valve is notifying affected users and data protection authorities, while CEVA Logistics is investigating the incident.
Data of European Steam hardware customers 'likely compromised', Valve says
Valve has reported that European Steam hardware customers have likely had some of their data compromised. The extent of the breach and the specific data affected are still under investigation.
Valve Warns Steam Machine Owners Their Personal Details May Have Been Stolen
Valve is notifying European Steam Machine owners that their personal details, including name, address, and phone number, may have been compromised due to a cyberattack on a logistics company. The company warns customers to be vigilant against potential phishing scams using their information. Valve also noted that Steam Guard codes and passwords remain secure.
Framework customer information was accessed as part of a data breach
Framework confirmed a data breach where customer information was accessed, though no payment details were compromised. The company is investigating the incident.
IBM Report: 92% of AI-Related Breaches Hit Firms With Weak Access Controls
An IBM report indicates that 92% of companies experiencing AI-related data breaches had inadequate access controls, suggesting a fundamental security flaw rather than an AI-specific vulnerability. These AI-related incidents cost an average of $5.33 million, with breaches involving AI-powered attacks reaching $6.04 million.
Vatican scrambles to patch 'phishing goldmine' app promoted by the Pope: 'Prayer infrastructure on the framework you learn in week 2 of a Node.js bootcamp'
The Vatican's official 'Click To Pray' app, promoted by Pope Francis, was found to have significant security vulnerabilities exposing over 700,000 user emails and personal data. A white-hat hacker revealed the issue, which remained unaddressed for months until public disclosure, turning the app into a 'phishing goldmine' for malicious actors targeting less tech-savvy users.
Saturday Safety Dance
The Pope's official prayer app has suffered a data breach, exposing the information of over 700,000 users. The incident, reported by The Register, highlights a significant security lapse in the application.
PSA: An important security update from MassivelyOP
MassivelyOP experienced a security incident due to a WordPress vulnerability that affected millions of sites. While no damage to the site or company servers is apparent, user data such as email addresses, names, and hashed passwords may have been exposed. The company is notifying the public out of caution and recommending users reset their passwords.