
Valve is warning Steam customers in Europe that their personal and delivery information may have been compromised in a cyberattack targeting CEVA Logistics, the company responsible for shipping Steam hardware to European buyers.
According to a security notification sent by Valve, the attack occurred between July 29 and August 1, 2026. Valve says it learned on August 7 that information belonging to some Steam customers was likely accessed during the incident.
CEVA receives customer data from Valve that is necessary to deliver physical Steam hardware, such as the Steam Deck and related products. The logistics provider retains this information for up to 90 days after an order, prompting Valve to notify customers whose details may still have been stored in CEVA's systems when the breach occurred.
CEVA Logistics is a large international freight and logistics company providing transportation, warehousing, and supply-chain services for businesses worldwide. Valve uses the company as a logistics partner for Steam hardware deliveries in Europe.
Valve says the compromised information may include customer:
- Names
- Street addresses, postal codes, cities, countries
- Phone numbers
- Steam account email addresses
- Type and price of hardware ordered
More sensitive Steam account information was not exposed through CEVA, as the gaming giant assured. The logistics company does not have access to Steam passwords, Steam Guard authentication codes, payment information, or details about unrelated purchases.

The primary risk for affected customers is now targeted phishing and social-engineering attacks. Because attackers may possess both contact information and details about a recent Steam hardware purchase, fraudulent messages could appear significantly more convincing than generic phishing attempts.
Valve warned customers to expect fake emails, SMS messages, or phone calls impersonating Steam, Valve, or delivery companies. Attackers could reference the victim's address or order information before asking them to pay a supposed customs or redelivery fee, confirm a shipment, or sign in to a fake Steam website.
Valve says affected users do not need to change their Steam passwords because Steam account credentials were not part of the information available to CEVA.
The company also reminded customers that legitimate Steam Support interactions take place through help.steampowered.com, while genuine Steam login pages are hosted on official Steam domains, including store.steampowered.com, steampowered.com, steamcommunity.com, and help.steampowered.com. Steam Support and delivery companies will never request a Steam password or Steam Guard code.
Valve says it is pressing CEVA for additional information on the scope and cause of the breach and is notifying the relevant data protection authorities in the affected European countries. CEVA has reportedly isolated and taken affected systems offline and brought in external investigators.







Leave a Reply