Valve has confirmed that an unconfirmed number of Steam customers in Europe may have had their personal data compromised following a cyberattack on their shipping partner, CEVA Logistics. The breach occurred between July 29, 2026, and August 1, 2026, with Valve identifying the potential data exposure on August 7.
What Data Was Compromised
CEVA Logistics retains specific delivery information for up to 90 days to facilitate the shipment of physical hardware. According to Valve, the attacker likely accessed the following details for affected customers:
- Full name
- Street address, city, postal code, and country
- Phone number
- Email address associated with the Steam account
- Type and price of the ordered hardware
Valve has clarified that the attack was limited to the logistics provider's systems. Payment information, account passwords, and Steam Guard codes remain secure and were not involved in the incident.
Security Recommendations for Affected Users
Valve warns that users may receive fraudulent communications—including emails, SMS, or phone calls—that attempt to appear legitimate by citing specific hardware order details. The company emphasizes the following safety protocols:
- Check login URLs: Only enter credentials on official domains including
store.steampowered.com,www.steampowered.com, orsteamcommunity.com. - Ignore requests for fees: Treat any message asking for customs payments or redelivery fees as a phishing attempt.
Company Response
Valve is currently working with CEVA Logistics to determine the full scope of the breach. The shipping partner has isolated the affected systems and engaged outside investigators to manage the incident. Valve is also in the process of notifying data protection authorities in the relevant European countries. Impacted customers with further questions can reach out to Valve via their support portal or through their designated contact point: Artana Digital GmbH, Alstertwiete 3, 20099 Hamburg, Germany.
