Valve Warns Steam Hardware Customers About Data Breach


valve hardware breach
Image credit: Valve

Valve is warning Steam hardware customers in Europe about a data breach that exposed personal information after a cyberattack hit shipping partner CEVA Logistics.

According to reports from Reddit users, CEVA handles deliveries of Steam hardware orders across Europe. Attackers reportedly accessed CEVA systems between July 29 and August 1, 2026.

Valve learned on August 7 that Steam customer information may have been exposed and has started contacting customers whose data was likely affected.

Steam hardware customer data was exposed

The compromised information includes customer names, addresses, phone numbers, and email addresses.

Attackers may also have obtained details about the type of Steam hardware customers ordered and how much they paid for it.

Valve says the exposed information was limited to data CEVA required to ship physical hardware orders.

Steam accounts and payment details were not affected

The breach did not expose Steam account credentials or payment information. Information about customers’ other Steam purchases was also not compromised.

Steam Guard codes were not exposed either, meaning Valve says affected users do not need to change their Steam passwords or modify their account settings because of the incident.

Valve warns customers about phishing attacks

Valve says attackers could use the stolen information to launch convincing phishing campaigns against affected customers.

Scammers may impersonate Valve, Steam, CEVA, or other delivery companies through emails, text messages, and phone calls.

Because attackers may know a customer’s real address and hardware order details, fraudulent messages could appear more convincing than typical phishing attempts.

For example, attackers could claim that a delivery needs confirmation, request a small customs or redelivery payment, or direct customers to a fake Steam login page.

Valve is advising customers to treat unexpected requests involving their Steam hardware deliveries with caution.

CEVA Logistics investigates the cyberattack

CEVA has isolated systems affected by the attack and hired external investigators to examine the incident.

Valve is also pressing CEVA for additional details about the scope of the breach and how attackers managed to access its systems.

The company is notifying data protection authorities in affected European countries.

CEVA had previously informed several European retailers on August 1 that a cyberattack had disrupted operations at eight warehouses across Europe.

In other news, Valve has confirmed that the memory and storage crisis is escalating, while Steam Deck sales have dropped 82% following the price increase.

Via BleepingComputer

More about the topics: Hardware, security, Valve

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages