TL;DR
Valve has warned Steam hardware customers in Europe that a cyberattack on shipping partner CEVA Logistics likely exposed their contact, delivery and order details. Passwords, payment data and Steam Guard codes were not affected, but the exposed information could support convincing phishing attempts.
Valve has warned Steam hardware buyers in Europe that a cyberattack on its shipping partner, CEVA Logistics, likely compromised customer contact, delivery and order information. The company said passwords, payment details and Steam Guard codes were not affected, but cautioned recipients that the exposed data could be used in targeted phishing messages and fraudulent calls.
According to Valve’s customer notification, the attack affected CEVA systems between July 29 and August 1, 2026. Valve said it learned on August 7 that information belonging to some Steam customers was likely among the data taken. CEVA was still investigating the intrusion when Valve issued its warning.
The information that may have been compromised includes a buyer’s name, street address and location details, along with a phone number and email address. The email address is the one connected to the customer’s Steam account. The attacker may also have obtained the type and price of the hardware ordered.
CEVA receives those details so it can deliver physical Steam products in Europe and, according to Valve, retains the information for up to 90 days after an order. Valve said it contacted every customer it could reasonably assume was affected. Other Steam purchases and account information were outside the reported exposure because CEVA does not have access to those records.
Valve warns Steam hardware buyers after CEVA cyberattack
A cyberattack on European shipping partner CEVA Logistics likely exposed customer contact, delivery and hardware-order details. Valve says passwords, payment information and Steam Guard codes were not affected—but the stolen context could make phishing attempts unusually convincing.
What may have been taken—and what stayed out of reach
CEVA receives the information needed to deliver physical Steam products. It does not receive Valve’s wider account, authentication or payment records.
| Data category | Reported status | Why CEVA had it | Practical risk |
|---|---|---|---|
| Name and delivery address | ~Likely exposed | Parcel fulfilment | Personalised courier scams |
| Phone number and Steam email | ~Likely exposed | Delivery contact | Email, SMS and fraudulent calls |
| Hardware type and price | ~Likely exposed | Order fulfilment | Highly credible order references |
| Steam account password | ✓Not affected | Never provided to CEVA | No direct credential exposure reported |
| Payment details | ✓Not affected | Never provided to CEVA | No payment-data exposure reported |
| Steam Guard codes | ✓Not affected | Never provided to CEVA | Codes remain private unless users reveal them |
| Other Steam purchases | ✓Outside scope | CEVA has no access | No wider purchase-history exposure reported |

SS304 Hinge Steamer Maintenance Door Lock Pressing Hinge Environmental Protection Equipment Door Hand Wheel(Color 1)
Spring Rebound Rotary Grip Frame: Built-in elastic reset structure supports free horizontal rotation of the outer pull frame,…
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
How real delivery data becomes a convincing scam
Accurate personal details do not prove that a message is genuine. In this incident, those details are precisely what attackers may use to manufacture trust.
Data is combined
A name, address, product and exact price create a detailed customer profile.
A message arrives
The sender poses as Valve, Steam Support, CEVA or another courier.
Urgency is added
A customs fee, failed delivery or expiring account warning pressures action.
The trap closes
A false payment or login page attempts to capture money or credentials.

Gettysburg and Stories of Valor – The Civil War
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Four dates define the known breach window
Valve linked its customer-warning scope to CEVA’s delivery-data retention period, but did not publish a specific range of affected order dates.
Valve has not disclosed how many Steam customers were affected.
No country-by-country breakdown of European exposures is available.
The attacker, intrusion method and any publication of stolen data remain unidentified.

Whirlpool W10044609A Genuine OEM Hose Kit For Steam Dryers, 5 Feet Black Accessories – Replaces 211053, 3389955, 4319131, 4392905, 4392905R, 661592, 687104, 694044, 694045, PS407504, W10830966
This product is a Factory Certified Accessory. These three words represent quality parts and accessories designed specifically for…
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Three actions matter now
Valve says customers do not need to change their passwords solely because of this incident. The priority is resisting messages that exploit the exposed delivery context.
Type the address yourself
Open help.steampowered.com directly instead of following links in unexpected emails, texts or adverts.
Refuse secret requests
Never provide a password or Steam Guard code to anyone claiming to represent Steam Support or a courier.
Verify payment claims
Treat surprise customs, redelivery and small-fee requests as fraudulent until independently confirmed.
Treat all of them as fake.
Valve’s advice on unsolicited messages, calls and texts
gaming hardware shipping insurance
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Exposed Details Raise Phishing Risk
The combination of names, addresses and order details could allow criminals to create messages that appear closely connected to a real Steam hardware delivery. A fraudulent email or text could identify the product, quote its price or repeat the recipient’s address, giving the message an appearance of legitimacy.
Valve told affected customers to expect possible email, SMS and telephone scams posing as Steam, Valve or a courier. Such messages may request a small customs or redelivery payment, direct the recipient to a false login page or ask for account credentials. Buyers do not need to change their Steam passwords solely because of this incident, Valve said, since authentication credentials were not held by CEVA.
CEVA Handles European Hardware Deliveries
Valve uses CEVA Logistics to ship physical Steam hardware to customers across Europe. That work requires Valve to provide delivery information, but CEVA does not receive payment data, account passwords or Steam Guard codes, according to the notice.
The warning applies to customers whose delivery information may have remained in CEVA’s systems during the affected period. Valve did not provide a specific order-date range for the recipients, but linked the notification scope to CEVA’s retention period of up to 90 days.
“Certain information about Steam customers, including you, was likely compromised.”
— Valve, in its customer notification
Breach Scope Still Under Investigation
It is not yet clear how many Steam customers were affected, which European countries recorded exposures or whether every listed data category was taken for every recipient. Valve described the information as likely compromised, reflecting the incomplete investigation.
Neither Valve nor CEVA identified the attacker, disclosed the method used to enter the systems or said whether the stolen information had appeared online. It also remains unknown whether fraud attempts have been directly linked to the breach. Any message claiming knowledge of a Steam hardware order should be treated cautiously even if it contains accurate personal information.
Investigators Trace the CEVA Intrusion
Valve said it is seeking a fuller account from CEVA of what data was taken and how the attack occurred. The company is also notifying data protection authorities in affected countries. CEVA has isolated the affected systems, taken them offline and brought in outside investigators, according to Valve’s notice.
Affected buyers can contact Valve through help.steampowered.com or write to its designated contact point, Artana Digital GmbH in Hamburg, Germany. Valve advises users to type official Steam addresses directly into a browser and never give a password or Steam Guard code to anyone claiming to represent Steam Support or a courier.
Key Questions
What Steam customer information may have been exposed?
The potentially compromised records include names, delivery addresses, phone numbers and email addresses, as well as the type and price of the ordered Steam hardware.
Were Steam passwords or payment details stolen?
Valve said CEVA does not have access to customer passwords, payment information, Steam Guard codes or wider purchase records. Those categories were not reported as affected.
Should affected customers change their Steam passwords?
Valve said a password change is not required because of this incident. Customers should still avoid links in unsolicited messages and use only official Steam domains when signing in.
How can buyers identify a possible scam?
Buyers should distrust unexpected messages that mention a hardware order and request a delivery fee, customs payment or account login. Steam Support handles account matters through help.steampowered.com and will not request a password or Steam Guard code.
Where did the report originate?
The customer warning was reported after Valve emailed affected European buyers about the incident involving CEVA Logistics.
Source: GamingOnLinux
Source: GamingOnLinux