Full Breakdown
Valve warns European Steam hardware buyers after CEVA Logistics cyberattack
8/11/2026, 7:47:55 PM
Breach Overview
Between July 29 2026 and August 1 2026, a cyberattack compromised the internal databases of CEVA Logistics, the third-party fulfillment partner that ships Valve’s Steam hardware to customers in Europe. Valve learned of the intrusion on August 7 and confirmed that attackers likely accessed delivery-related information CEVA retains for up to 90 days after an order. Exposed data includes customers’ full names, shipping addresses, phone numbers, the email tied to their Steam account, and itemised hardware purchase details (type and price). Payment information, passwords and Steam Guard codes were not stored by CEVA.
Timeline
- July 29 2026 – Attack begins on CEVA’s systems.
- August 1 2026 – Attack continues; data is extracted.
- August 7 – Valve is notified and determines personal information was “likely compromised.”
- August 10 2026 – Valve emails affected European customers with breach notifications.
Data Exposed
- Street address, postal code, city, country
- Email address (used for the Steam account)
- Hardware SKU, model and purchase price (e.g., Steam Deck OLED, Valve Index VR kit)
No financial details, passwords, or Steam Guard data were part of the breach.
Valve’s Response
Valve stressed that its own storefront and core servers remain uncompromised; the incident is confined to the external logistics provider. The company reported the breach to data-protection authorities in the impacted countries.
In its customer email, Valve warned that the stolen delivery information enables highly targeted phishing that may appear to come from Steam, Valve or a courier such as FedEx, UPS, DHL, DPD or Royal Mail. Scammers could quote a victim’s address to lend credibility and request payment of a small customs or redelivery fee, or ask the user to “verify” the order on a fraudulent site. Valve advises users to treat any unsolicited messages about past hardware deliveries as fake and to verify delivery status only through the official Steam account or the courier’s own tracking tools.
Impact and Recommendations
The primary risk is hyper-targeted spear-phishing. Because attackers possess exact purchase prices and delivery addresses, fraudulent messages can convincingly mimic legitimate courier communications. Valve recommends:
1. Do not click links in unexpected emails or SMS messages referencing a hardware order.
2. Verify any delivery inquiry by logging directly into the Steam account or using the official courier’s tracking website.
3. Enable two-factor authentication on all accounts that share the Steam email address.
4. Report suspicious messages to Valve’s support channels.
