Valve Warns European Steam Hardware Buyers After Shipping Partner Cyberattack Exposes Customer Data

news
Valve Warns European Steam Hardware Buyers After Shipping Partner Cyberattack Exposes Customer Data

Valve has warned some European customers that personal information connected to recent Steam hardware orders may have been exposed after a cyberattack hit its shipping partner CEVA Logistics.

The incident took place between July 29 and August 1, 2026. Valve said it learned on August 7 that customer data was likely affected.

The exposed information was limited to details required for hardware deliveries. Valve says Steam passwords, payment information and Steam Guard codes were not part of the breach.

What information may have been exposed

Data typeStatus
Full namePotentially exposed
Street addressPotentially exposed
Postal code and cityPotentially exposed
CountryPotentially exposed
Phone numberPotentially exposed
Email addressPotentially exposed
Product typePotentially exposed
Product pricePotentially exposed
Steam passwordNot exposed
Payment detailsNot exposed
Steam Guard codesNot exposed

The breach appears to affect customers whose hardware order information was still stored by CEVA. The company reportedly keeps this data for around 90 days, so recent buyers are the group most likely to be involved.

Valve has not said that all European Steam hardware customers were affected.

Valve warns about targeted phishing attempts

The main risk now is phishing.

Because attackers may have access to both contact information and order details, fraudulent messages could appear more convincing than normal spam. A scammer could mention the product you ordered, your address or other delivery information before asking you to take action.

Valve says customers should be cautious about messages requesting delivery confirmation, customs charges, small additional fees or account verification.

Attackers could use email, phone calls or text messages to make those requests appear legitimate.

The exposed information could also make it easier to create fake messages that appear to come from a courier or Steam related service.

Password changes are not required

Valve says affected customers do not need to change their Steam passwords because login credentials were not available to CEVA and were not included in the compromised information.

Steam account security therefore appears to be separate from this incident.

Valve also reiterated that Steam Support will not request your password or Steam Guard code.

That remains important because phishing messages following a breach often attempt to turn basic personal information into access to more sensitive accounts.

If a message asks for your login credentials or authentication code, it should be treated as suspicious regardless of how much accurate information about your order it contains.

Recent Steam hardware orders are the main concern

The incident is specifically connected to physical Steam hardware shipments handled by CEVA in Europe.

That means customers who only purchased digital games or who did not recently order hardware through the affected delivery network should not automatically assume their information was involved.

The data exposure also does not appear to include payment card details.

Still, names, addresses, phone numbers and email addresses are useful information for social engineering attacks, particularly when combined with knowledge of a recent expensive hardware purchase.

That makes vigilance more important even without a direct Steam account compromise.

Investigation is still underway

Valve says it is continuing to press CEVA for a clearer explanation of how the breach happened and how much customer information was accessed.

The company is also notifying relevant data protection authorities in affected European countries.

CEVA has reportedly isolated the compromised systems, taken them offline and brought in outside investigators to help determine the scope of the attack.

More details could emerge as that investigation continues.

For affected customers, the immediate risk is less about losing control of a Steam account and more about receiving convincing scams built around legitimate order information. The safest approach is to avoid clicking unexpected links, ignore requests for passwords or Steam Guard codes and verify any delivery issue independently rather than responding directly to a message.

Discover: News

Discussion (0)

Be the first to comment.