Project Chintan

Valve Warns Steam Users of Data Breach via Logistics Partner

Valve has alerted Steam hardware customers in Europe to a potential data breach affecting personal and order information. A cyberattack on logistics firm CEVA Logistics between July 29 and August 1, 2026, may have exposed customer names, addresses, and order details.

· 3 min read
Updated

Key takeaways

  • Valve has alerted European Steam hardware customers to a data breach affecting personal and order details.
  • The breach occurred through a cyberattack on logistics partner CEVA Logistics between July 29 and August 1, 2026.
  • Customer names, delivery addresses, phone numbers, and order specifics may have been compromised.
  • Payment details and Steam account credentials were not exposed in the incident.

What Happened

Valve has notified Steam hardware customers across Europe about a potential data breach stemming from a cyberattack on CEVA Logistics, the company responsible for distributing its physical products in the region. The incident granted unauthorized access to CEVA systems from July 29 to August 1, 2026. Valve became aware of the potential compromise of customer information on August 7 and has commenced sending notifications to affected individuals.

The exposed data may include customers’ names, delivery addresses, telephone numbers, and email addresses. Information regarding the type and price of Steam hardware ordered could also have been accessed. This combination of details poses a phishing risk, as fraudulent communications could appear convincing by using authentic delivery information.

Valve stated that payment information, Steam passwords, and Steam Guard authentication codes were not compromised through CEVA, as the logistics provider does not handle these details during hardware deliveries. Other Steam account information and purchases unrelated to the affected shipments were also not part of the compromised delivery records.

Key Facts

  • The cyberattack on CEVA Logistics occurred between July 29 and August 1, 2026.
  • Valve learned of the data compromise on August 7, 2026.
  • Exposed information may include customer names, delivery addresses, telephone numbers, email addresses, and details about Steam hardware ordered.
  • Payment information, Steam passwords, and Steam Guard codes were not exposed.
  • CEVA Logistics is responsible for distributing Valve's physical products in Europe.
  • The attack affected part of CEVA's European contract logistics operations and disrupted eight warehouses.
  • Other companies affected by the CEVA intrusion include Bol, De Bijenkorf, Ajax, ING, and Ace & Tate.
  • CEVA Logistics generated $18.3 billion in revenue in 2025 and operates over 1,000 warehouses globally.

Why It Matters

The breach highlights the significant risks associated with data exposure through third-party logistics providers. The combination of personal details and actual purchase information can make social-engineering attacks, such as phishing or fraudulent requests for payment, more convincing and harder for consumers to identify.

Valve cautioned customers to be vigilant for fraudulent emails, text messages, and telephone calls referencing their Steam hardware purchases. Attackers might impersonate Valve, Steam, or delivery companies, using genuine order details to establish credibility. Such scams could demand customs fees, additional delivery payments, or prompt users to visit fake websites to steal Steam credentials or financial data.

Background

CEVA Logistics retains delivery information supplied by Valve for up to 90 days after an order to manage returns and fulfillment issues. Valve initiated warnings to customers whose orders might have been within CEVA’s systems during the intrusion, rather than limiting notifications to those whose data was definitively confirmed as stolen.

Valve advised that the CEVA incident does not necessitate changing Steam passwords or account settings, as the compromised systems did not contain such credentials. The company also reminded users that Steam Support communicates only through its official service and will not request passwords or Steam Guard codes.

The CEVA intrusion has broader implications, affecting multiple businesses whose products pass through its facilities. CEVA has stated that security procedures were activated, an investigation is underway, and compromised infrastructure has been isolated. Some services have since been restored, and outside investigators have been engaged.

Story by Project Chintan

Related stories