started · updated
CEVA Logistics cyberattack exposes European Steam hardware customer data
A cyberattack on CEVA Logistics, a major shipping partner for Valve, has exposed the personal data of European customers who purchased Steam hardware. The breach occurred between July 29 and August 1, 2026, and was reported to Valve on August 7.
The compromised information includes customer names, street addresses, postal codes, cities, countries, phone numbers, and the email addresses associated with Steam accounts. Additionally, details regarding the type and price of the hardware ordered may have been stolen. Because CEVA retains delivery data for up to 90 days, the breach potentially affects anyone who purchased devices such as the Steam Deck, Steam Machine, or Steam Controller within the last three months.
Valve has clarified that sensitive account security information, including passwords, payment details, and Steam Guard codes, was not compromised because CEVA does not have access to those systems. However, Valve has issued a warning to customers regarding the high risk of targeted phishing attacks. Scammers may use the stolen order details to pose as Valve, Steam, or delivery companies, requesting small fees for customs or redelivery to trick users into providing further information.
CEVA Logistics has isolated the affected systems and engaged external investigators. Valve is currently pressing the logistics firm for a full investigation into the scope and method of the breach and is in the process of notifying relevant data protection authorities across Europe.
Entities
CEVA Logistics · Steam · Steam Controller · Steam Deck · Steam Machine · Valve · Valve Corporation
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 13 SOURCES] Valve is requesting a full investigation from CEVA regarding the scope and method of the breach. wolfsgamingblog.com · 1001infos.net · fr.ign.com · www.gram.pl · wccftech.com · +8 more
- [● 31 SOURCES] Passwords, payment details, and Steam Guard codes were not compromised. wolfsgamingblog.com · www.komputerswiat.pl · dawn.fi · nosmokesport.com · 1001infos.net · +26 more
- [● 27 SOURCES] Exposed data includes names, addresses, phone numbers, email addresses, and product order details. wolfsgamingblog.com · www.komputerswiat.pl · dawn.fi · nosmokesport.com · 1001infos.net · +22 more
- [● 31 SOURCES] The breach affects customers who purchased Steam hardware in Europe within the last 90 days. wolfsgamingblog.com · www.komputerswiat.pl · dawn.fi · nosmokesport.com · 1001infos.net · +26 more
- [● 27 SOURCES] The cyberattack on CEVA Logistics occurred between July 29 and August 1, 2026. wolfsgamingblog.com · www.komputerswiat.pl · dawn.fi · nosmokesport.com · 1001infos.net · +22 more