Valve has warned some European customers that personal information connected to recent Steam hardware orders may have been exposed after a cyberattack hit its shipping partner CEVA Logistics.
The incident took place between July 29 and August 1, 2026. Valve said it learned on August 7 that customer data was likely affected.
The exposed information was limited to details required for hardware deliveries. Valve says Steam passwords, payment information and Steam Guard codes were not part of the breach.
What information may have been exposed
| Data type | Status |
|---|---|
| Full name | Potentially exposed |
| Street address | Potentially exposed |
| Postal code and city | Potentially exposed |
| Country | Potentially exposed |
| Phone number | Potentially exposed |
| Email address | Potentially exposed |
| Product type | Potentially exposed |
| Product price | Potentially exposed |
| Steam password | Not exposed |
| Payment details | Not exposed |
| Steam Guard codes | Not exposed |
The breach appears to affect customers whose hardware order information was still stored by CEVA. The company reportedly keeps this data for around 90 days, so recent buyers are the group most likely to be involved.
Valve has not said that all European Steam hardware customers were affected.
Valve warns about targeted phishing attempts
The main risk now is phishing.
Because attackers may have access to both contact information and order details, fraudulent messages could appear more convincing than normal spam. A scammer could mention the product you ordered, your address or other delivery information before asking you to take action.

Valve says customers should be cautious about messages requesting delivery confirmation, customs charges, small additional fees or account verification.
Attackers could use email, phone calls or text messages to make those requests appear legitimate.
The exposed information could also make it easier to create fake messages that appear to come from a courier or Steam related service.
Password changes are not required
Valve says affected customers do not need to change their Steam passwords because login credentials were not available to CEVA and were not included in the compromised information.
Steam account security therefore appears to be separate from this incident.
Valve also reiterated that Steam Support will not request your password or Steam Guard code.
That remains important because phishing messages following a breach often attempt to turn basic personal information into access to more sensitive accounts.
If a message asks for your login credentials or authentication code, it should be treated as suspicious regardless of how much accurate information about your order it contains.
Recent Steam hardware orders are the main concern
The incident is specifically connected to physical Steam hardware shipments handled by CEVA in Europe.
That means customers who only purchased digital games or who did not recently order hardware through the affected delivery network should not automatically assume their information was involved.
The data exposure also does not appear to include payment card details.
Still, names, addresses, phone numbers and email addresses are useful information for social engineering attacks, particularly when combined with knowledge of a recent expensive hardware purchase.
That makes vigilance more important even without a direct Steam account compromise.
Investigation is still underway
Valve says it is continuing to press CEVA for a clearer explanation of how the breach happened and how much customer information was accessed.
The company is also notifying relevant data protection authorities in affected European countries.
CEVA has reportedly isolated the compromised systems, taken them offline and brought in outside investigators to help determine the scope of the attack.
More details could emerge as that investigation continues.
For affected customers, the immediate risk is less about losing control of a Steam account and more about receiving convincing scams built around legitimate order information. The safest approach is to avoid clicking unexpected links, ignore requests for passwords or Steam Guard codes and verify any delivery issue independently rather than responding directly to a message.



Discussion (0)
Be the first to comment.