Valve Warns European Steam Hardware Buyers: Shipping Data Likely Compromised in CEVA Logistics Breach

JMarvv
JMarvv
August 10, 2026 at 4:13 PM · 4 min read
Valve Warns European Steam Hardware Buyers: Shipping Data Likely Compromised in CEVA Logistics Breach

If you have bought a Steam Deck, Steam Machine, or Steam Controller in Europe, Valve has a warning for you: your delivery details may have been exposed in a cyberattack on its shipping partner. Valve's own systems were not hit, but the data shared with logistics provider CEVA Logistics was "likely compromised," and Valve is now warning customers to expect follow-on phishing scams. Here is what we know, what is still unclear, and how to protect yourself.

The Breach: What Happened at CEVA Logistics

Valve emailed European customers about a cyberattack on CEVA Logistics, its shipping partner for Steam hardware, that took place between July 29 and August 1. According to a copy of the customer notification shared with affected buyers, Valve was told on August 7 that certain Steam customer information "was likely compromised." CEVA has not yet confirmed the full scope of the attack, and the investigation is still ongoing.

It is worth being precise about the language here. Some headlines have stated that data was "stolen," but Valve's official wording is more cautious: "likely compromised." That distinction matters because CEVA is still determining exactly what was exfiltrated and what may have been accessed without being taken.

CEVA handles European delivery for Steam Deck, Steam Machine, and Steam Controller, and buyers of all three hardware lines have reported receiving Valve's notification email. Valve's own systems were not affected. This is a third-party supply-chain breach, meaning the attack targeted the logistics partner, not Steam's infrastructure.

The Breach: What Happened at CEVA Logistics
The Breach: What Happened at CEVA Logistics

What Data Was Exposed (and What Wasn't)

The potentially exposed data includes names, physical addresses, phone numbers, email addresses, and purchase or order information. In short, this is the delivery-related information that Valve shares with CEVA to ship physical hardware to customers.

The good news for Steam users: Steam account credentials, passwords, payment data, and Steam Guard codes were not exposed, according to Valve. That is a meaningful distinction. The breach did not touch the systems that guard your actual Steam account.

No affected-customer count has been published, and speculation would be unhelpful. Valve says it is pressing CEVA for details on exactly what was taken and how the attack happened. Until CEVA completes its investigation, the full picture will remain incomplete.

Why Valve Warns About Phishing "Fake Messages"

The most actionable part of Valve's warning is the phishing alert. Valve explicitly tells affected customers to expect "fake messages": phishing emails, SMS texts, and phone calls impersonating Valve, Steam, or delivery companies.

This is a high-risk scenario because attackers may already have accurate delivery data. A scam email that references your real name, your actual address, and a real order is far more convincing than a generic phishing attempt. Attackers may request customs fees, redelivery payments, or account logins through these fake messages.

It is worth repeating the key rule: legitimate communications from Valve or delivery companies will never ask for customs payments, passwords, or Steam Guard codes via email or SMS. If a message asks for any of those things, it is a scam regardless of how official it looks.

What Data Was Exposed (and What Wasn't)
What Data Was Exposed (and What Wasn't)

Wider Fallout: Not Just Steam

The impact of this breach goes well beyond Steam customers. The CEVA cyberattack disrupted operations at eight European warehouses and caused shipping delays across multiple retailers. Dutch platforms Bol and de Bijenkorf also warned customers of a possible data leak through the same logistics partner, according to Dutch broadcaster NOS.

That wider context matters. This is not a Valve-specific compromise. It is a logistics provider that handles shipping for multiple companies, and the blast radius may extend well beyond Steam hardware buyers.

Because the affected countries fall under the European Union's General Data Protection Regulation (GDPR), Valve says it is in the process of notifying data protection authorities. That is a process worth watching as the story develops. GDPR notification requirements often push companies to disclose breach details sooner than they otherwise might.

What Affected Customers Should Do Now

If you have purchased Steam hardware in Europe, assume that any unexpected message about a shipment could be a trap. The steps below can help you protect yourself.

  • Treat unsolicited emails, texts, or calls about shipments, customs fees, or redelivery with suspicion. Do not click links or download attachments from unexpected messages, even if they reference real order details. Attackers may have your actual delivery information, which makes their messages look legitimate.
  • Never provide passwords, Steam Guard codes, or payment information in response to an email, SMS, or phone call. No legitimate company will ask for these through those channels.
  • Verify any delivery or redelivery request by going directly to the official shipper's site or through Steam's client and official support pages. Do not use links from the suspicious message itself. Navigate to the site directly instead.
  • Keep an eye on your inbox for follow-up notifications from Valve, and report suspicious messages where possible. Steam has built-in reporting tools for phishing attempts, and your email provider likely has spam reporting as well.

A Developing Story With a Clear Takeaway

Valve's reassurance that Steam accounts and payment data were not exposed is meaningful. Your Steam library is safe. But the leaked delivery details are enough to power convincing phishing campaigns that could cost you money or compromise your personal information if you take the bait.

Until CEVA completes its investigation, treat every unexpected shipping message as suspect, verify independently, and never share your Steam Guard codes. This article will be updated as more details emerge from CEVA and regulators.

Comments

0 Comments

Join the Conversation

Share your thoughts, ask questions, and connect with other community members.

No comments yet

Be the first to share your thoughts!