Valve has reported a significant data breach involving its European shipping partner, CEVA Logistics, which has impacted buyers of its Steam hardware products. This breach affected customers who purchased items such as the Steam Deck, Steam Machine, and Steam Controller across Europe.
Details of the Data Breach
The cyberattack on CEVA Logistics took place from July 29 to August 1, 2026. Valve became aware of the breach on August 7 and promptly alerted affected customers through a security email. The breach potentially exposed delivery-related data that CEVA stores for up to ninety days following an order.
The compromised information includes customers’ full names, addresses, phone numbers, email addresses linked to their Steam accounts, and details about purchased hardware. Valve has assured customers that sensitive data such as Steam account credentials, passwords, and payment information remain secure, as CEVA did not have access to these details.
Wider Impact and Previous Incidents
The breach at CEVA Logistics is part of a larger disruption affecting its European operations. Reports indicate that the attack hindered operations in eight CEVA warehouses, causing shipment delays for many retail clients. Notable companies like Bol, De Bijenkorf, Ajax, ING, and Ace & Tate, all reliant on CEVA for logistics, have also reported data exposure.
This incident is not CEVA’s first encounter with cyber threats. In September 2025, a group named CoinbaseCartel claimed responsibility for a breach that compromised extensive database information. The connection between the two incidents remains unclear.
Potential Risks and Customer Guidance
Security experts caution that the leaked information could facilitate phishing and fraud attempts, particularly with the aid of AI tools that customize scam messages. Customers are advised to be vigilant against emails impersonating Steam, especially those requesting payments or login credentials.
Valve has emphasized the importance of verifying communications through official Steam channels and staying aware of potential scam attempts leveraging the exposed data. This breach highlights vulnerabilities in digital supply chains, where even robust internal security measures can be undermined by third-party partners.
Strengthening security protocols and fostering vigilance among customers are crucial in mitigating the risks posed by such data breaches.
