Gaming & Live Streaming

Valve confirms Steam hardware buyers' data exposed in CEVA Logistics cyberattack

Valve has begun notifying European customers who ordered Steam hardware that their personal information may have been exposed following a cyberattack on CEVA Logistics, the company that handles Steam hardware...

AAdmin
August 10, 2026
2 min read
Valve confirms Steam hardware buyers' data exposed in CEVA Logistics cyberattack

European customers' data compromised after breach at Valve's regional shipping partner

Image credit: Valve News by Vikki Blake Contributor Published on Aug. 10, 2026, 5:46 p.m. Follow Valve Valve has begun notifying European customers who ordered Steam hardware that their personal information may have been exposed following a cyberattack on CEVA Logistics, the company that handles Steam hardware deliveries across the region.

News of the breach first surfaced on ResetEra and Reddit , where affected customers began posting screenshots of Valve's notification email earlier today.

In the email, seen by GamesIndustry.biz , Valve said the attack on CEVA occurred between July 29 and August 1, and that it learned of the breach on August 7.

Because CEVA retains delivery-related data for up to 90 days after an order is placed, Valve is notifying everyone it believes was affected within that window.

The compromised information includes customers' names, street addresses, postal codes, cities, countries, phone numbers, the email addresses tied to their Steam accounts, and the type and price of the hardware ordered. It's thought buyers of the Steam Deck, Steam Machine and Steam Controller are primarily affected, although Valve insists that no payment information, passwords, Steam Guard codes or other account data were affected and that customers don't need to change their passwords or account settings.

Valve warned customers to expect phishing attempts via email, SMS, or phone that reference their order, some of which may quote a customer's real address to appear legitimate. The company reiterated that Steam Support only operates through help.steampowered.com and will never request a password or Steam Guard code.

CEVA confirmed the breach in a statement to TechCrunch , saying the intrusion affected part of its European contract logistics operations.

The France-headquartered logistics giant said the attack disrupted at least eight of its European warehouses. The breach has also reportedly affected several banks and retailers that similarly rely on CEVA for shipping alongside Valve.

Valve said it is pressing CEVA for further detail on the scope of the breach and how it occurred, and is notifying data protection authorities in the affected countries. The exact number of customers affected has not been disclosed.