← All stories
business

Valve Warns European Steam Hardware Buyers of Data Breach at Shipping Partner CEVA Logistics

5 outlets8/10/2026

The short version

Valve is emailing Steam Machine and Steam Controller customers in Europe after a cyberattack on shipping partner CEVA Logistics exposed personal information, though payment data and passwords appear safe.

via Rock Paper Shotgun

Valve has begun notifying Steam Machine and Steam Controller customers in Europe that their personal information may have been compromised following a cyberattack on CEVA Logistics, the company that ships Steam hardware across the continent. According to an email from Valve, the attack occurred between July 29 and August 1, 2026, and Valve says it learned of the breach on August 7. News of the breach first surfaced through Steam users posting the email on Reddit and ResetEra, as neither Valve nor CEVA has issued a public statement.

The compromised information reportedly includes customer names, phone numbers, email addresses, postal addresses, countries of residence, and details of Steam hardware purchases. Valve's email states that payment information, passwords, and Steam Guard codes were not accessible to CEVA and were not affected. CEVA retains delivery-related data for up to 90 days after an order is placed, meaning customers who ordered Steam hardware in Europe from around late April onward could be impacted. Valve says it is emailing everyone it can assume was affected.

Valve is warning affected customers to expect fake messages via email, SMS, or phone that reference their hardware order and appear to come from Steam, Valve, or a delivery company. These messages may quote a customer's address to appear legitimate and could ask recipients to confirm a delivery, pay a customs or redelivery fee, or sign in to 'verify' an order. Valve says all such messages should be treated as fake, noting that Steam Support never contacts users via email, Steam chat, or Discord, and only handles account issues through its official help page. Customers are advised not to click links in suspicious messages, to type the Steam store address in directly instead, and to never share passwords or Steam Guard codes.

CEVA has reportedly isolated the affected systems, taken them offline, and brought in outside investigators. Valve says it is pressing CEVA for the full scope of what data was taken and how, and is in the process of notifying data protection authorities in the affected countries.

There is some discrepancy in reported timelines: while Valve's email says it learned of the attack on August 7, Dutch outlet NOS reported that two companies, Bol and De Bijenkorf, were informed of the cyberattack as early as August 1, according to Kotaku.

Valve has been shipping Steam Machines to winners of its pre-order lottery over the past couple of months, and Steam Controllers continue to ship as well, though new controller orders placed now are not expected to arrive until sometime in 2027.

Every angle

5 outlets · 5 takes

How each outlet is covering this story. Go straight to the one with the angle you want — we send you to the source.

All sources

Follow this story’s topics

Storyline

Valve/Steam Hardware Data Breach via CEVA Logistics

1 story →
Replies

No replies yet.

Sign in to reply.

Get the weekly digest

The week's stories in the categories you pick — in your inbox. No spam, unsubscribe anytime.