Valve says customer data was not exposed in CEVA cyberattack
Steam shoppers can stop worrying about their data falling into the wrong hands.

- Valve says attackers did not access the system that processed European Steam hardware orders.
- The company previously warned that names, addresses, contact details, and order history might have been exposed.
- Passwords, payment data, and Steam Guard codes were not involved in the incident.
- Valve still tells customers to treat order-related emails, texts, and calls as fake.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Valve is walking back its warning to European Steam hardware buyers, confirming that personal data wasn’t accessible to attackers who breached its logistics partner, CEVA Logistics.
“While CEVA has not yet concluded its full investigation, we have learned that the attack was limited to a subset of its systems. In particular, the system that processed your Steam hardware order was not affected,” Valve explained in an email addressed to affected buyers.
“There is currently no indication that your data was accessible to the attacker at any time during this incident. We are sorry for the delay while this was confirmed and apologize for any confusion or alarm that resulted from our prior notification.”
Last month, the American video game developer and publisher warned European Steam hardware customers that their data was potentially exposed in a cyberattack on its shipping partner, CEVA Logistics.
This included names, addresses, contact details, and order history. No passwords, payment data, or Steam Guard codes were involved in the incident.
Affected users were advised to remain vigilant about any suspicious activities from scammers.
Expect fake messages – email, SMS, or phone – that mention your hardware order and appear to come from Steam, Valve, or a delivery company. They may quote your address back to you to prove they’re genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to “verify” your order. Treat all of them as fake,Valve told European customers.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
CEVA Logistics is a global logistics and supply chain company with over 1,300 locations worldwide. The company employs over 110,000 workers and generated over $18.3 billion in revenue last year.
In August, multiple businesses warned customers that their personal information was likely stolen in a security incident at CEVA Logistics, including Dutch department store De Bijenkorf, online retailer bol, soccer club Ajax, financial institution ING, optician chain Ace & Tate, and Pokémon merchandise seller the Pokémon Center.
CEVA Logistics recently discovered that personal information of current and former employees was also stolen, such as IDs, Social Security numbers, bank details, family details, salary data, and absence records.