Valve warns European Steam hardware buyers of data breach at shipping partner CEVA Logistics

Valve began notifying European customers on August 10 that a cyberattack on its shipping partner, CEVA Logistics, exposed personal delivery information tied to Steam hardware orders. The breach did not touch Valve's own systems, passwords, or payment information — the compromised data came entirely from CEVA, which handles the physical shipping of Steam Deck, Steam Controller, and Steam Machine orders to European customers.
According to Valve's notification, the exposed information includes customers' names, street addresses, postal codes, cities, countries, phone numbers, the email address linked to their Steam account, and the type and price of the hardware they ordered. Passwords and payment card details were not part of the exposure.
Timeline of the Breach
The attack window ran from July 29 to August 1, 2026. Valve says it learned of the incident on August 7 and began notifying affected customers three days later, on August 10. Because CEVA retains delivery data for roughly 90 days after shipment, anyone who received Steam hardware in Europe within the past three months could be affected. Neither Valve nor CEVA has disclosed exact numbers of impacted customer records. Dutch retailers Bol and De Bijenkorf were reportedly informed of the same CEVA incident on August 1 and separately warned their own customers.
Why Shipping Data Is a Scam Goldmine
Security researchers note that delivery data is particularly valuable to scammers because it makes phishing attempts far more convincing than generic messages. An email, text, or phone call that correctly references a customer's real name, home address, and the specific hardware they ordered is significantly more likely to succeed than a generic "your account is suspended" message, since it mimics the kind of legitimate communication a real shipping company would send.
Malwarebytes researchers reported finding more than 7,500 compromised datasets containing over 8.4 billion records circulating on the dark web during the first half of 2026 alone, underscoring how readily this type of data gets traded and reused for follow-on scams once exposed.
Valve's Security History
This is not Valve's first brush with a security incident, though the company's core systems were not directly compromised this time. In May 2025, a threat actor calling itself Machine1337 attempted to sell what was purported to be a dataset of 89 million Steam user records, though the data later turned out to be older SMS messages containing expired two-factor authentication codes routed through a third-party intermediary Valve says it never partnered with. Valve's most serious direct breach came in November 2011, when an incident exposed records from 35 million users, including usernames, emails, and encrypted credit card details.
What Affected Customers Should Do
Valve is advising customers to treat any message referencing a recent Steam hardware order — email, SMS, or phone call — as fake, even if it accurately quotes their address or order details. The company notes that Steam Support never contacts users through email, Steam Chat, or Discord, and only handles account issues through its official help page. While a password reset isn't strictly necessary since login credentials weren't exposed, Valve recommends enabling Steam Guard two-factor authentication and remaining skeptical of unsolicited delivery-related communications in the weeks ahead.
Originally reported by Malwarebytes. Read the original article for additional details.
View original source