[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVEqFbv0zZwZn9ED2dGrzR0xS5TXJLLk7hvyKV3BwQEY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"e7b3e441-450a-4687-b16a-2eb7d061b03d","third-party-logistics-breach-exposes-steam-customer-data","4b21faeb-4077-41e3-92b2-4005455ba5db","Third-Party Logistics Breach Exposes Steam Customer Data","Valve's data breach originated not within its own systems, but at a third-party shipping partner, CEVA Logistics — a classic supply chain security failure. Attackers accessed CEVA's systems over a four-day window, exfiltrating personally identifiable information (PII) including names, addresses, phone numbers, and email addresses. This incident highlights how an organization's security posture is only as strong as its weakest vendor link, and that customer data shared with partners inherits the risk profile of those partners. Even when core systems like payment platforms remain uncompromised, stolen PII creates significant downstream risk through targeted phishing and social engineering campaigns.","**Immediate actions:**\n- Audit all third-party vendors and partners who have access to customer PII and assess their current security controls.\n- Notify affected customers promptly with clear guidance on recognizing phishing attempts that may use stolen data.\n- Revoke or rotate any shared credentials or API tokens used by the compromised logistics partner.\n\n**Long-term improvements:**\n- Establish contractual security requirements (e.g., SOC 2, ISO 27001 compliance) for all vendors who handle customer data.\n- Implement data minimization principles so third parties receive only the PII strictly necessary to fulfill their function.\n- Create a formal Third-Party Risk Management (TPRM) program with regular vendor security assessments and right-to-audit clauses.\n\n**Detection measures:**\n- Require vendors to provide timely breach notification SLAs (e.g., within 24–72 hours of discovery) as part of contractual agreements.\n- Monitor dark web and threat intelligence feeds for early signs of customer data exposure linked to your supply chain.\n- Establish continuous logging and alerting for data egress events across any systems where third-party access is granted.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 15 – Service Provider Management","CIS Control 3 – Data Protection","NIST SP 800-53 SA-9 – External Information System Services","NIST SP 800-53 AC-20 – Use of External Information Systems","NIST Privacy Framework PR.DS-P – Data Security for Privacy","GDPR Article 28 – Processor Obligations","GDPR Article 33 – Notification of Data Breach to Supervisory Authority","GDPR Article 5(1)(c) – Data Minimisation","ISO\u002FIEC 27001 Annex A 5.19 – Information Security in Supplier Relationships","ITIL Service Design – Supplier Management Process","published","2026-08-10T12:20:18.961942+00:00","2026-08-10T12:20:18.672+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fvalve-notifies-steam-hardware-customers-of-a-data-breach\u002F","valve-notifies-steam-hardware-customers-of-a-data-breach-3603f0","Valve notifies Steam hardware customers of a data breach",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"5b25dd90-1411-4cd1-b545-7d876920b08b","2026-08-10","afternoon","ThreatNoir Afternoon Brief — August 10","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-10\u002Fthreatnoir-afternoon-brief-2026-08-10.mp3"]