Steam Hardware Shipping Partner CEVA Logistics Suffers Data Breach
Valve is notifying European Steam customers of a data breach at its shipping partner, CEVA Logistics, exposing names, addresses, and order details.

Video game publisher Valve has begun informing European customers about a significant data breach affecting its third-party shipping partner, CEVA Logistics. The incident, which occurred between July 29 and August 1, 2026, saw attackers gain access to sensitive customer information related to Steam hardware orders.
Valve learned of the breach on August 7 and has since initiated customer notifications. The compromised data includes customer names, street addresses, postal codes, cities, countries, phone numbers, and the email addresses associated with their Steam accounts. Additionally, details about the type and price of the hardware ordered were also exposed.
CEVA Logistics, responsible for shipping Steam hardware to customers across Europe, requires this delivery information to fulfill orders. According to Valve, this is the specific data that the attackers likely targeted. The logistics company retains customer information for up to 90 days post-order, meaning Valve is contacting all customers whose data falls within this retention window.
Fortunately, Valve has stated that other sensitive account information, such as payment details, passwords, Steam Guard codes, and other account-related data, was not accessed during the attack. CEVA Logistics does not have access to this type of information.
In response to the breach, Valve is warning its customers to be vigilant against potential phishing attempts. Attackers may use the leaked information, such as customer addresses, to craft convincing fake messages via email, SMS, or phone. These fraudulent communications could impersonate Steam, Valve, or delivery companies, potentially asking recipients to confirm deliveries, pay small customs fees, or log into fake websites to "verify" orders.
Valve strongly advises customers to treat all such unsolicited communications as fake and to avoid clicking on suspicious links or providing any personal information. The company has emphasized that no password changes or adjustments to account security settings are necessary at this time.
Valve is actively pressing CEVA Logistics for more detailed information regarding the exact scope of the breach and the methods used by the attackers. The company is also cooperating with data protection authorities in the affected European countries. CEVA Logistics has reportedly isolated the affected systems, taken them offline, and engaged external cybersecurity experts to investigate the incident and bolster their defenses.