Steam Hardware Shipping Partner CEVA Logistics Suffers Data Breach
Valve is notifying European Steam customers of a data breach at its shipping partner, CEVA Logistics, exposing names, addresses, and order details.

Video game publisher Valve has begun informing European customers about a significant data breach affecting its third-party shipping partner, CEVA Logistics. The incident, which occurred between July 29 and August 1, 2026, saw attackers gain access to sensitive customer information related to Steam hardware orders.
Valve learned of the breach on August 7 and has since initiated customer notifications. The compromised data includes customer names, street addresses, postal codes, cities, countries, phone numbers, and the email addresses associated with their Steam accounts. Additionally, details about the type and price of the hardware ordered were also exposed.
CEVA Logistics, responsible for shipping Steam hardware to customers across Europe, requires this delivery information to fulfill orders. According to Valve, this is the specific data that the attackers likely targeted. The logistics company retains customer information for up to 90 days post-order, meaning Valve is contacting all customers whose data falls within this retention window.
Fortunately, Valve has stated that other sensitive account information, such as payment details, passwords, Steam Guard codes, and other account-related data, was not accessed during the attack. CEVA Logistics does not have access to this type of information.
In response to the breach, Valve is warning its customers to be vigilant against potential phishing attempts. Attackers may use the leaked information, such as customer addresses, to craft convincing fake messages via email, SMS, or phone. These fraudulent communications could impersonate Steam, Valve, or delivery companies, potentially asking recipients to confirm deliveries, pay small customs fees, or log into fake websites to "verify" orders.
Valve strongly advises customers to treat all such unsolicited communications as fake and to avoid clicking on suspicious links or providing any personal information. The company has emphasized that no password changes or adjustments to account security settings are necessary at this time.
Valve is actively pressing CEVA Logistics for more detailed information regarding the exact scope of the breach and the methods used by the attackers. The company is also cooperating with data protection authorities in the affected European countries. CEVA Logistics has reportedly isolated the affected systems, taken them offline, and engaged external cybersecurity experts to investigate the incident and bolster their defenses.
The data breach at Ceva Logistics, initially reported as impacting European contract logistics operations, has now been confirmed to have affected specific clients including Valve, Bol, De Bijenkorf, Ajax, and ING. The incident, which occurred between July 29 and August 1, appears to be a supply chain attack where attackers gained access to delivery-related information, potentially including names, addresses, phone numbers, and order details for European customers. While Ceva states no other global systems were affected, the full scope and impact on these clients are still being investigated.
The cyberattack on CEVA Logistics has expanded its impact, with reports now indicating that eight European warehouses were affected, leading to disruptions for multiple retailers and customers. Notably, users of the Steam gaming platform in Europe have been warned about potential exposure of their personal and purchase information due to the breach. While CEVA Logistics has not publicly commented on the incident, affected companies like Bol and De Bijenkorf have begun notifying their customers about the potential data compromise, which could include names, addresses, and order details.
Valve's advisory further details that the breach occurred between July 29 and August 1, 2026, and that CEVA Logistics stores delivery data for approximately 90 days. This means any European customer who received hardware in the last three months could be affected. The exposed data includes names, addresses, phone numbers, Steam email addresses, order details, and hardware types, but crucially excludes passwords and payment information. Valve is advising affected customers to be highly skeptical of any unsolicited communications regarding their hardware orders, even if they contain accurate personal details.
The cyberattack on Ceva Logistics, which disrupted operations at eight European warehouses and impacted customers like Valve, has also affected Dutch retailers Bol and De Bijenkorf. These retailers have confirmed that customer data, including names, addresses, and order details, may have been compromised due to the incident, though payment information was reportedly not affected.
The Pokémon Center has confirmed a data breach affecting its UK and German customers, stemming from a cyberattack on its logistics partner, CEVA Logistics. This incident, which began July 30, 2026, exposed customer names, addresses, phone numbers, emails, and order contents, leading to the cancellation of some orders. CEVA Logistics, a major global shipping firm, has confirmed disruptions at eight European warehouses, impacting multiple clients beyond Pokémon Center, including Valve, highlighting a broader trend of targeting logistics providers for extensive data exposure.