Valve Warns European Steam Customers of Data Breach After Logistics Cyberattack

European Steam customers face phishing risks after a CEVA Logistics cyberattack exposed names, contact details, and delivery data.

Story Highlights

  • The breach affects certain European customers who purchased a Steam Machine or Steam Controller.
  • Exposed information may include names, contact details, and shipping addresses.
  • Affected customers should be alert for phishing emails, text messages, and fraudulent delivery notices.

Valve is warning some European Steam hardware customers that their personal information was exposed following a cyberattack on one of its logistics partners.

What Information Was Exposed?

According to a notification email sent to affected customers, attackers had access to CEVA Logistics’ servers between July 29 and August 1, 2026. CEVA is the company Valve uses to ship Steam hardware orders to customers in Europe, and Valve says it learned of the breach on August 7.

“CEVA receives specific delivery-related information from Steam to be able to ship physical hardware to customers in Europe, and told us these are the details the attacker likely took,” Valve said in the email. “Because CEVA retains this information for up to 90 days after that order, we are sending this message to all customers we can assume were impacted.”

The compromised records include affected customers’ names, addresses, phone numbers, email addresses, and the type and price of the products they ordered. Valve has contacted people whose details were potentially included in the breach.

Crucially, the attack did not involve Steam’s own systems. CEVA does not have access to Steam login credentials, account data, Steam Guard codes, or payment information, so Valve says none of that was exposed. That distinction limits the immediate damage, but it does not make the leak harmless. Contact and delivery information gives scammers enough material to create convincing messages that appear to come from Valve, Steam, or a courier.

Steam Machine And Controller Buyers Should Expect Scams

Steam wishlists and gifting
Steam wishlists and gifting are made easier thanks to the new update.

Valve’s email specifically warned that affected customers may be targeted by email, SMS, or voice phishing attempts using the stolen data.

“They may quote your address back to you to prove they’re genuine,” the company said. “They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to verify your order. Treat all of them as fake.”

Valve also clarified that no account action is required on the customer’s end. “You do not need to change your Steam password, and you don’t need to do anything to your account settings,” the email added.

A scammer could reference a real hardware purchase, delivery address, or phone number to make a fake shipping update look legitimate, then use that credibility to request a payment, account login, or further personal information under the pretense of resolving a delivery issue.

Valve said it is pressing CEVA for the full scope of what was taken and how, and that it is notifying data protection authorities in the affected countries. CEVA has reportedly isolated the impacted systems, taken them offline, and brought in outside investigators. Valve’s disclosure follows CEVA separately informing several European retailers on August 1 that a cyberattack had disrupted operations at eight of its European warehouses.

If you receive an unexpected message concerning a Steam Machine or Steam Controller order, do not use its links. Open Steam or the relevant courier’s official website independently and check the order there.

Did you find this helpful? Leave feedback below.

Thanks! Do share your feedback with us. ⚡

How can we make this post better? Your help would be appreciated. ✍

Subscribe to our newsletter and get up-to-speed gaming updates delivered to your inbox.

We don’t spam! Read more in our privacy policy.

Summary
[su_list icon="icon: plus" icon_color="#0F90CE"] Story Highlights The breach affects certain European customers who purchased a Steam Machine or Steam Controller. Exposed information may include names, contact details, and shipping addresses. Affected customers should be alert for phishing emails, text messages, and fraudulent delivery notices. [/su_list] Valve is warning some European Steam hardware customers that their…
Ahmed Faizan is eXputer's News Editor who’s been keeping up with the gaming and technology industries since he was 14. If there’s a buzz in the industry, Faizan's news report will be among the first you’ll read on the internet. He’s got a Bachelor's in Journalism and has several years worth of experience reporting on the gaming industry. Experience: 6+ Years || Education: Bachelor's in Journalism || Published 200+ News Stories

Related Articles

Join Our Community

Enjoyed this article? Discuss the latest gaming news, get expert help with guides and errors, and chat about all things gaming on eXputer Forums and Discord Server. Connect with fellow gamers who share your passion by becoming a part of eXputer's community.