Valve Corporation confirms European Steam hardware
Valve Corporation has confirmed that personal data belonging to European customers who purchased Steam hardware was exposed following a cyberattack on CEVA Logistics, the company’s third-party shipping partner in the region. The breach, which occurred between July 29 and August 1, 2026, compromised sensitive delivery information for buyers of products like the Steam Deck, Steam Machine, and Steam Controller.
Valve became aware of the incident on August 7, 2026, and began notifying affected customers via email today, August 10. While no payment information, passwords, or Steam Guard codes were compromised, the exposed data includes names, street addresses, postal codes, cities, countries, phone numbers, the email addresses tied to Steam accounts, and details on the type and price of hardware ordered.
Scope of the Steam hardware data exposure
The cyberattack on CEVA Logistics primarily impacted European customers who had ordered Valve’s gaming hardware. CEVA, a global logistics giant, handles shipping for Valve across the continent, making its systems a critical link in the supply chain for popular devices.
Because CEVA Logistics retains delivery-related data for up to 90 days post-order, Valve is reaching out to all customers within that timeframe who might be affected. This means a significant number of recent hardware purchasers could have had their details exposed.
Details of compromised personal information
The extent of the data exposed is quite granular, covering essential personal identifiers. It includes a customer’s full name, their complete street address, postal code, and city, alongside their country and phone number. Attackers also gained access to the email address associated with their Steam account.
Crucially, the type of hardware ordered and its price were also part of the compromised information. This level of detail could make affected customers prime targets for highly convincing phishing scams.
What wasn’t exposed: Payment and account security
Thankfully, Valve has been quick to reassure customers that more critical financial and account details remained secure. No payment information, such as credit card numbers or banking details, was involved in the breach. Similarly, customer passwords, Steam Guard two-factor authentication codes, or other sensitive Steam account data were not accessed. CEVA Logistics simply doesn’t store that kind of information.
This distinction is important; while the personal data exposure is serious, the direct threat to Steam accounts themselves is mitigated. Customers aren’t being advised to change their passwords or account settings.
The CEVA Logistics cyberattack incident timeline
The cyberattack against CEVA Logistics took place over several days, specifically between July 29 and August 1, 2026. This period allowed attackers to gain access to and potentially exfiltrate data from parts of the company’s European contract logistics operations.
Valve learned of the breach on August 7, giving them a few days to assess the situation before beginning customer notifications. The widespread email alerts to affected European Steam hardware buyers started today, August 10.
Broader impact on CEVA Logistics clients
This incident isn’t isolated to Valve’s operations. CEVA Logistics, a subsidiary of the CMA CGM Group, handles logistics for numerous businesses. Reports indicate the cyberattack disrupted at least eight of its European warehouses, impacting other clients as well.
Dutch retailers bol and De Bijenkorf have already issued alerts concerning compromised customer data due to the CEVA hack. Even the Dutch football club Ajax disclosed a security incident tied to CEVA, affecting its webshop order processing and potentially exposing names, addresses, emails, phone numbers, and order histories for its fans. This paints a picture of a far-reaching incident with ripple effects across multiple sectors.
Valve’s response and customer warnings
In response to the breach, Valve is actively engaging with CEVA Logistics to understand the full scope and nature of the compromise. They’ve also taken steps to notify data protection authorities in the various affected European countries, aligning with regulatory requirements like GDPR.
The company is urging customers to remain vigilant against potential phishing attempts. Scammers could use the exposed delivery details to craft highly convincing emails, SMS messages, or phone calls that appear legitimate by referencing real addresses and hardware orders.
Advising vigilance against phishing attempts
Valve has issued clear guidelines to help customers protect themselves. They’ve reiterated that legitimate Steam Support communications only occur through help.steampowered.com. Furthermore, Steam will never request a password or Steam Guard code via email or phone. Users should also ensure that any Steam-related pages they visit are on the official domains: store.steampowered.com, www.steampowered.com, or steamcommunity.com.
This warning highlights the secondary risk of data breaches: the potential for follow-on social engineering attacks. With specific purchase and address details now potentially in the hands of bad actors, the danger of targeted scams increases considerably, requiring extra caution from consumers.
Understanding supply chain security in gaming
This incident underscores a growing vulnerability within the technology sector: the security of third-party logistics and supply chain partners. Gaming companies, like many others, increasingly rely on external vendors for various operations, including the physical delivery of hardware.
CEVA Logistics itself has faced cyber threats before; the CoinbaseCartel ransomware group reportedly targeted the firm in late 2025. Even Valve isn’t a stranger to data security challenges, having experienced a major breach affecting 35 million Steam users in 2011 and a third-party SMS provider incident in 2025.
Broader industry trends in cyberattacks
The gaming industry, with its valuable user data and high-profile companies, makes an attractive target. But the issue extends far beyond gaming. Cyberattacks against logistics and supply chain firms have become a disturbing trend, affecting major players across various industries.
Incidents like the NotPetya malware attack crippling Maersk in 2017, ransomware hitting JAS Worldwide in 2024, or the widespread impact of the SolarWinds supply chain compromise illustrate the systemic risk. These attacks can cause massive disruptions, financial losses, and significant data exposure for numerous clients down the line.
The interconnected nature of global commerce means a vulnerability in one part of the supply chain can have cascading effects, impacting thousands or even millions of consumers indirectly. As companies like Valve launch new hardware products, their security considerations must now extend beyond immediate digital platforms.
This includes every partner in their delivery network, highlighting that security challenges often become heightened with new hardware releases and expanded supply chains. The incident serves as a stark reminder of these complex vulnerabilities.
Moving forward: Enhancing data protection and trust
For Valve, this breach through a trusted partner emphasizes the need for rigorous vetting and continuous monitoring of third-party vendors. While they acted quickly to inform customers and authorities, the incident could still chip away at consumer trust, a critical asset in the competitive gaming hardware market.
CEVA Logistics, for its part, is now under increased scrutiny. The company has isolated affected systems, taken them offline, and engaged outside investigators. The long-term implications for CEVA will depend on how transparently and effectively they address the root causes of the cyberattack and bolster their defenses.
Consumers, unfortunately, bear the brunt of such breaches. While Valve didn’t store payment details with CEVA, the exposure of names, addresses, and purchase history highlights the persistent risk in an increasingly digital world. This incident serves as a stark reminder for all online shoppers to be extra cautious about unsolicited communications, especially those referencing personal orders, even when they appear highly convincing.

