Steam Machine Controller User Data Leak After Cyber Attack
.png)
What Is the Steam Machine and Controller User Data Leak?
The Steam Machine and Controller user data leak is a security breach that occurred when Valve Corporation's European supplier, CSL Computer, suffered a cyber attack. This incident exposed personal information belonging to customers who purchased Steam Machines and Steam Controllers through the European distributor, potentially compromising names, addresses, and order details.
Valve Corporation, the manufacturer of the Steam Machine and Steam Controller, confirmed the breach after CSL Computer's systems were compromised. The Steam Machine is a line of pre-built gaming PCs running SteamOS, while the Steam Controller is a gamepad designed for Steam's living-room platform. This security incident affects the supply chain between Valve and its regional hardware partners, creating a risk for customers who purchased hardware through non-Valve channels.
"The Steam Machine and Controller user data leak exposed personal customer information through a third-party European supplier, not through Valve's own Steam platform infrastructure."
Key Facts
| Attribute | Value |
| Attack Target | CSL Computer, Valve's European supplier |
| Affected Products | Steam Machine, Steam Controller |
| Manufacturer | Valve Corporation |
| Attack Date | Reported October 2015 |
| Data Exposed | Customer names, shipping addresses, email addresses, order histories |
| Payment Data | Not confirmed as exposed |
| Valve Account Data | Not compromised |
| Notification Method | Email alert to affected customers |
What Data Was Exposed in the CSL Computer Breach?
The CSL Computer breach exposed customer order information, including names, physical addresses, email addresses, and purchase histories for Steam Machines and Steam Controllers. Valve stated that the compromised data was limited to the European supplier's order database and did not include Steam account credentials or payment information.
Valve's official statement to affected customers explained the scope of the incident. The company noted that CSL Computer's systems were accessed by an unauthorized party, and the data that could have been viewed was restricted to the information customers provided when ordering hardware from the European supplier.
"We have been in contact with CSL and have confirmed that the attacker was able to view order information for Steam Machines and Steam Controllers purchased through their site."
— Valve Corporation, customer notification via Kotaku
"The CSL Computer breach exposed order information for Steam Machines and Steam Controllers, but Valve confirmed that Steam account credentials and payment data were not part of the compromised dataset."
How Does This Attack Affect Steam Users?
Steam users who purchased hardware through CSL Computer face potential phishing and social engineering risks because their email addresses and shipping details were exposed. Users who bought directly from Valve's Steam store were not affected by this breach, as the compromised systems belonged to the European supplier, not Valve's own infrastructure.
The attack highlights a critical distinction in digital supply chains: third-party vendors may hold customer data that the primary platform does not control. For affected users, the primary risk is targeted phishing emails that reference their Steam Machine or Controller purchase to build trust. Valve advised affected customers to be cautious of unsolicited communications and to verify any requests for personal information.
"Steam users who purchased hardware through CSL Computer face phishing risks from the exposed order data, while users who bought directly from Valve's Steam store were not affected by this breach."
Who Is This Attack Relevant To?
This attack is relevant to Steam Machine and Steam Controller owners in Europe who purchased their hardware through CSL Computer, as well as to security researchers studying supply chain vulnerabilities in the gaming industry. It also serves as a cautionary example for any consumer who buys hardware through regional distributors rather than directly from the manufacturer.
The breach demonstrates that purchasing through authorized resellers introduces additional data-handling parties into the transaction. While Valve's own security measures were not bypassed, the company's customers still faced exposure because of a partner's vulnerability. This incident is part of a broader pattern of gaming-related data breaches in the 2015 period, including the separate compromise of the Steam community forums in July 2015.
"This attack is relevant to European Steam Machine and Controller owners who purchased through CSL Computer, and it demonstrates how third-party supply chain partners can become the weakest link in customer data security."
Common Questions
Was my Steam account password compromised in this breach?
No. Valve confirmed that the CSL Computer breach only exposed order information from the European supplier's systems. Steam account credentials, including passwords and login data, were not part of the compromised dataset.
Should I change my Steam password after this attack?
While not strictly necessary for this specific breach, changing your Steam password is a reasonable precaution if you used the same credentials elsewhere. The exposed email addresses could enable phishing attempts, so enabling Steam Guard two-factor authentication is strongly recommended.
How do I know if I was affected by the CSL Computer data leak?
Valve sent email notifications to customers who purchased Steam Machines or Steam Controllers through CSL Computer. If you did not receive an email but believe you purchased through the European supplier, contact CSL Computer directly to confirm whether your order data was exposed.
Sources and Methodology
This article is based on reporting from Kotaku, which obtained Valve's customer notification regarding the CSL Computer breach. The original report was published on October 9, 2015, and details the scope of the data exposure and Valve's response. No additional sources were synthesized for this article.
All facts, dates, and statements are drawn directly from the Kotaku report. No currency conversions or unit translations were required, as the source material did not contain financial figures. This article was last updated on May 24, 2025.