Valve has begun notifying an unspecified number of Steam hardware customers that their personal details were compromised following a cyberattack on CEVA Logistics, the company's European shipping partner. While the incident is currently unconfirmed regarding the total number of individuals impacted, reports indicate that the breach occurred between July 29 and August 1, 2026.
Quick Facts
- Source of Breach: CEVA Logistics, Valve’s European shipping partner.
- Compromised Data: Names, email addresses, physical addresses, and phone numbers.
- Confirmed Secure: Valve states that Steam account data and purchase/payment information were not affected.
- Discovery Date: Valve reported learning of the attack on August 7, 2026.
Scope of the Incident
The breach appears limited to customers who purchased Steam hardware, such as controllers or Steam Machines, within Europe. Because CEVA Logistics retains shipping information for up to 90 days after an order, anyone who received a shipment in that window may be at risk. While Valve has not released an official press statement, affected customers have confirmed receiving direct email notifications regarding the exposure of their contact information.
The timeline of the attack remains under investigation. While Valve notes the compromise occurred at the end of July, Dutch news outlet NOS reported that other companies utilizing the same logistics provider were alerted to the breach as early as August 1.
Player Safety Recommendations
Valve has explicitly warned customers to be cautious of potential social engineering attempts. Because names, emails, and phone numbers were exposed, attackers may attempt to contact users with fraudulent messages disguised as official communication from Valve or logistics services regarding their hardware orders. Users are advised to avoid clicking suspicious links or providing additional information in response to unsolicited messages claiming to be related to the shipment.
