European Valve customers' personal data exposed in shipping partner hack

Valve has begun contacting European customers who purchased Steam hardware, warning them that a cyberattack on its regional shipping partner, CEVA Logistics, likely exposed their personal delivery information. In emails shared by affected users on Reddit, Valve said the attack on CEVA Logistics took place between July 29 and August 1, 2026. The company said it learned of the likely data compromise on August 7.
CEVA Logistics is the France-headquartered firm that ships Steam hardware, including Steam Machines, Steam Controllers, and Steam Deck units, to customers across Europe on Valve's behalf. According to Valve, CEVA retains delivery-related customer information for up to 90 days after an order is placed, meaning anyone who bought Steam hardware in Europe within that window could be affected.
The exposed information includes customer names, addresses, countries, phone numbers, Steam account email addresses, and details of the hardware purchased. Valve said passwords, Steam Guard codes, and payment information were not stored by CEVA and were not part of the breach.
Valve told affected customers to expect fake messages by email, text, or phone referencing their hardware order and appearing to come from Steam, Valve, or a delivery company. The company said scammers may quote a customer's real address back to them to appear legitimate, then ask for a customs or redelivery fee, or request a login to "verify" the order.
Valve said all such messages should be treated as fraudulent, and that it is pressing CEVA Logistics for the full scope of what data was taken and how the breach occurred.
According to FreightWaves reporting cited by multiple outlets, the cyberattack affected eight CEVA warehouse hubs and caused shipping delays across Europe for several of the logistics firm's retail clients, including Dutch retailers De Bijenkorf and Bol. CEVA Logistics reported $18.3 billion in revenue last year and operates roughly 1,700 locations across 170 countries, serving clients beyond Valve.
CEVA said it is still investigating the scope of the attack and has isolated the affected systems. Valve said it plans to notify data protection authorities in the relevant European countries as the investigation continues. Valve has not disclosed how many customers were affected by the breach.









