Steam hardware purchasers in Europe exposed: data breach hits Valve’s logistics partner
Scammers are expected to use leaked details in attempts to extort money through fraudulent requests for delivery or customs fees.

Image by Cybernews.
- Valve says a CEVA Logistics cyberattack likely exposed delivery details of European customers who recently bought Steam hardware.
- Exposed data may include names, addresses, contact details, and purchase information, but not passwords, payment data, or Steam Guard codes.
- CEVA is investigating and isolated affected systems, while Valve plans to notify data protection authorities.
- Valve warns leaked order details could fuel phishing scams seeking fees or login information; other CEVA clients may be affected.
Valve is warning European Steam hardware customers that their delivery-related details were likely exposed in a cyberattack on its shipping partner, CEVA Logistics. The compromised data includes names, addresses, phone numbers, emails, and purchase information.
Multiple Steam users report receiving letters from Valve informing them about a cybersecurity incident that affected CEVA Logistics, a major shipping company and part of the CMA CGM group, between July 29th, 2026, and August 1st, 2026.
CEVA ships Steam hardware to customers in Europe.
“CEVA is still investigating this attack, but as Valve learned on August 7th, certain information about Steam customers, including you, was likely compromised,” the letters shared by users said.
Only users who purchased Steam hardware in the past 3 months are likely to be affected, as CEVA retains specific delivery-related information for up to 90 days after the order.
Steam lists several data records that may have been compromised, as follows:
- Name
- Street address, postal code, city, and country
- Phone number
- Email address – the same as the Steam account
- Type and price of the ordered product
“Additional information related to your Steam account or other purchases was not impacted.
CEVA does not have access to your payment information, passwords, Steam Guard codes or other information,” the letter, shared on Reddit, reads.
CEVA has yet to disclose the full scope of the incident, and Valve plans on notifying the data protection authorities. The shipping company has isolated affected systems and brought in outside investigators.
Valve warns users that phishing messages are likely. Fake emails, SMSes, or even phone calls might mention a hardware order and appear to be coming from Steam, Valve, the delivery company, or others, quoting the leaked information.
Scammers might attempt to ask for a delivery or redelivery fee, request a small customs fee, or trick users into signing in somewhere to “verify” the order. Treat any of these actions as fake.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Steam assures users that passwords are not affected by the incident – they do not need to take any action or change any account settings. Valve says it never handles account issues by email, Steam Chat, or Discord, and the support and couriers never ask for passwords or Steam Guard codes.
Multiple other retailers might be affected by the CEVA Logistics breach. According to a report by FreightWaves, the CEVA Logistics cyberattack caused shipping disruptions, with e-commerce companies, including De Bijenkorf and bol in the Netherlands, posting alerts to customers.
CEVA reported $18.3 billion in revenues last year. The company serves 1,700 locations in 170 countries.
“CEVA is big. I have gotten emails from 3 other companies that use CEVA for fulfillment,” one of the affected users said on Reddit.
Cybernews reached out to Valve for comment and will update this story with its response.