Valve Warns Steam Customers of Data Leak After CEVA Cyberattack
European customers who recently purchased Steam hardware are being warned to watch for convincing phishing attempts after a cyberattack against Valve’s logistics partner potentially exposed names, addresses, email addresses and order information.
Valve is notifying some European Steam customers that their personal information was likely compromised following a cyberattack targeting the company responsible for shipping Steam hardware across Europe.
The incident involves CEVA Logistics, a third-party logistics company used by Valve to deliver products including the Steam Deck, Steam Machine and Steam Controller to European customers. According to information provided by Valve, CEVA suffered a cyberattack between July 29 and August 1, 2026. Valve was informed on August 7 that certain Steam customer information was likely compromised.
The good news for affected Steam users is that the breach does not appear to have exposed Steam passwords, payment information or Steam Guard authentication codes.
However, the information potentially obtained by the attackers could still be particularly useful for phishing and social-engineering attacks.
What Steam Customer Information May Have Been Exposed?
Valve provides CEVA Logistics with the information necessary to process and deliver hardware orders in Europe. According to Valve’s notification, that delivery information is believed to be what the attackers potentially accessed.
The compromised information may include:
- Customer names
- Street addresses, postal codes, cities and countries
- Phone numbers
- Email addresses associated with Steam accounts
- The type of Valve hardware ordered
- The total price of the order
CEVA reportedly retains this delivery information for as long as 90 days after an order is placed, meaning customers who purchased qualifying Steam hardware during roughly the previous three months could potentially be affected.
Exactly how many Steam customers had their information exposed has not yet been publicly confirmed.
Steam Passwords and Payment Information Were Not Exposed
One important distinction is that the attack was against Valve’s logistics partner rather than Steam’s core account infrastructure.
Valve says CEVA does not receive customers’ Steam passwords, payment information or Steam Guard codes, and therefore those credentials were not exposed through this incident.
That means this isn’t the type of breach where affected customers necessarily need to immediately reset their Steam passwords or cancel their credit cards.
Valve has specifically told customers that they don’t need to change their Steam passwords or alter their account settings because of the incident.
The bigger concern is what criminals could potentially do with the personal and order information they obtained.
Valve Warns Customers to Expect Fake Messages
Valve is warning affected customers to be especially suspicious of emails, text messages and phone calls claiming to concern their recent hardware orders.
Because an attacker could potentially know a customer’s name, address, phone number, email address and exactly what Valve product they purchased, a phishing message could appear significantly more convincing than the typical random scam.
For example, an attacker could potentially send a message pretending to be from Valve, Steam or a delivery company and reference the customer’s actual hardware purchase.
They could then claim there is a problem with the delivery and request a small payment for customs, redelivery or another supposed shipping charge.
Another possibility would be directing the customer to a fraudulent Steam login page under the guise of “verifying” the order.
Valve has warned customers to treat messages like these as fraudulent, even when they contain accurate personal information such as the customer’s address.
That’s an important point because the information exposed in this incident gives scammers exactly the type of contextual information that can make a social-engineering attack appear legitimate.
CEVA Is Still Investigating the Cyberattack
The investigation into the breach remains ongoing.
Valve says it is continuing to press CEVA for more information regarding both the scope of the stolen data and exactly how the attackers gained access to it.
CEVA has reportedly isolated the systems affected by the attack, taken them offline and brought in outside investigators to examine the incident.
Additional reporting indicates that the CEVA breach has affected more than Valve. Other companies that rely on the logistics giant have also reported customer information being exposed as a result of the incident, suggesting the cyberattack extends beyond Steam hardware shipments alone.
What Should Steam Hardware Customers Do?
For customers who receive Valve’s notification, the most immediate concern is phishing rather than the security of their Steam account itself.
Be skeptical of unexpected messages regarding a Steam hardware purchase, particularly messages claiming that an additional payment is required.
Customers should avoid clicking login links contained in unsolicited emails or text messages and instead access Steam directly when checking their account.
The same caution should apply to supposed delivery companies requesting customs fees, redelivery charges or verification payments related to a Valve order.
Most importantly, customers shouldn’t assume that a message is legitimate simply because the sender knows their name, address or details about their recent purchase. Those are precisely the pieces of information that may have been compromised.
A Third-Party Breach Can Still Put Steam Customers at Risk
The incident also highlights one of the more complicated aspects of protecting customer information.
A company’s own servers don’t necessarily have to be compromised for its customers to be affected.
Valve describes itself as a company that makes games, Steam and hardware, but physically delivering those products requires working with outside companies. In this case, customer information provided to a logistics partner for the legitimate purpose of delivering hardware became part of the potential attack surface.
While Valve says critical Steam credentials and financial information weren’t involved, names, addresses, phone numbers and purchase histories can still provide cybercriminals with valuable ammunition.
For European Steam hardware customers who receive a notification about the CEVA incident, there’s no reason to panic or immediately change every Steam credential.
There is, however, a very good reason to be suspicious of the next message claiming there’s a problem with your Steam hardware delivery.
Stay with GamerXGeek for the latest Steam, PC gaming, cybersecurity and video game industry news.
Discover more from GamerXGeek
Subscribe to get the latest posts sent to your email.
