Today’s Menu (30-second skim)
- Valve Warns Steam Machine Buyers About Scam Messages After Cyberattack: A real shipping breach means fake Steam and delivery messages may now sound a lot more believable.
- SafePal Breach Exposes Order Data for Nearly 40,000 Customers: SafePal says wallet secrets were not exposed, but customer order details now give scammers a strong target list.
- French Taxpayers’ Data Stolen in Government Cyberattack: Stolen tax data can turn the next fake government email, call, or letter into a much more convincing scam.
1) Valve Warns Steam Machine Buyers About Scam Messages After Cyberattack

What happened (plain English): Valve said one of its European shipping partners, CEVA Logistics, was hit by a cyberattack. The exposed details appear to be shipping and contact information tied to hardware orders, including names, addresses, phone numbers, and email addresses. That means criminals may now know what some customers bought and where those items were supposed to go. Valve warned people to expect fake emails, texts, or phone calls that mention real order details. The company said customers should get help only through the official Steam help page.
Why it matters to you: This kind of scam works because the criminal sounds informed right away. A fake text about a “delivery problem” feels more real when it includes your name, address, or the item you ordered. One common trick is a message asking you to click a link to “reschedule” a shipment or pay a small fee. Another is a fake support call asking for your password or a one time code to “verify” the order.
How to protect yourself (do this):
- Do not click links in surprise messages about an order problem, even if the message knows your address or item.
- Open Steam or the shipping company yourself through the app or website you normally use.
- Never share a login code or password with someone claiming to be support.
Published: 2026-08-10
Source: CNET
2) SafePal Breach Exposes Order Data for Nearly 40,000 Customers

What happened (plain English): SafePal said a flaw in an order tracking plug-in exposed customer order information. The company said 39,798 customers were affected. The exposed data included names, physical addresses, and contact details. SafePal said the breach did not expose private keys, seed phrases, passwords, payment card numbers, or customer funds. Even so, the customer list is enough to help criminals build very believable scams.
Why it matters to you: If a scammer knows you bought a crypto wallet, they know exactly what kind of fear to use against you. You might get an email, call, or even a letter claiming your wallet needs an urgent security fix. One scam could ask you to “confirm” your recovery phrase to avoid losing access. Another could push you to move funds to a fake “safe” wallet controlled by the criminal.
How to protect yourself (do this):
- Treat every unexpected SafePal message, call, or letter as suspicious until you verify it on SafePal’s official website.
- Never type or read your seed phrase to anyone, no matter what problem they claim to be fixing.
- If you already shared your recovery phrase, move your assets to a new wallet you create yourself.
Published: 2026-08-16
Source: CoinDesk
3) French Taxpayers’ Data Stolen in Government Cyberattack

What happened (plain English): France’s Finance Ministry said taxpayer data was stolen in a cyberattack. Government records often contain enough personal information to make a fake message sound official and urgent. Even if no money is taken right away, stolen data can be reused later in phone calls, emails, texts, or mailed notices. This is why a breach announcement can create a second wave of danger after the original attack. People affected may now face tax messages that sound real because they are built with real details.
Why it matters to you: Government themed scams scare people because nobody wants to ignore a tax warning. A criminal could send a fake bill that uses real personal details to pressure someone into paying fast. Another scam could ask for identity documents “to confirm your file” and use them for identity theft. When a message sounds official, people are more likely to rush, and that is exactly what scammers want.
How to protect yourself (do this):
- Do not pay, click, or send documents because of a surprise tax message.
- Go to the tax agency’s real website or call the official number printed on a previous real notice.
- If a message demands urgent payment by gift card, crypto, or wire transfer, treat it as a scam.
Published: 2026-08-14
Source: Reuters
Grandma’s Firewall

This week’s simple rule:
A breach announcement is not a green light to trust the next message. When someone claims to help with a hacked account, order problem, or tax issue, go to the real company or agency yourself.
Two scripts you can steal:
- “I’m not going to fix this from your link or your phone number. I’ll open the real website or app myself.”
- “If this is real, I’ll contact the company using the number or website I already have – not the one in your message.”
