Full Breakdown
Valve Warns European Steam Hardware Buyers of Data Breach
8/10/2026, 7:59:23 PM
What Happened
Valve disclosed that its European shipping partner, CEVA Logistics, suffered a breach between July 29 and August 1. The intrusion exposed delivery-related information for customers who ordered Steam hardware—Steam Deck, Steam Machine, or Steam Controller—within the past 90 days. Exposed data may include names, mailing addresses, phone numbers and email addresses. Valve emphasized that payment details, passwords and Steam Guard codes were not stored by CEVA and therefore remain secure.
Background
Valve began taking reservations for its new Steam Machine and Steam Controller weeks before the breach window. CEVA Logistics handles the physical delivery of Steam hardware across Europe and retains order-related data for up to 90 days after shipment. This retention policy created the pool of information that attackers accessed.
Official Statements & Responses
The company urged users to treat any such contact as fraudulent and clarified that it will address account issues only through its official help site.
Verbatim Quotes
- “They may quote your address back to you to prove they’re genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to ‘verify’ your order,” — Steam Controller. Valve
- “Because CEVA retains this information for up to 90 days... we are sending this message to all customers we can assume were impacted,” — Steam Controller. Valve
- “They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to 'verify' your order. Treat all of them as fake.” — Steam Controller. Valve
What’s Next
Customers are advised to ignore unsolicited requests to confirm deliveries, pay customs fees, or verify orders, and to remain vigilant in the coming weeks. Valve confirmed there is no need to change Steam passwords or modify other account settings. The company will continue to monitor the situation and work with CEVA and regulators to prevent further misuse of the compromised information.
