Valve has notified European customers via email that CEVA Logistics, the third-party company that ships Steam hardware across Europe, was targeted in a cyberattack between July 29 and August 1, 2026. Valve says it learned on August 7 that customer data was likely compromised as a result.

Because CEVA handles delivery logistics, the exposed data is limited to information tied to hardware orders: full name, street address, postal code, city, country, phone number, the email address linked to the customer's Steam account, and the type and price of the product ordered. CEVA retains this information for about 90 days to fulfill orders, so only customers who placed hardware orders within that window are affected. Valve stresses that account-level information was not touched — CEVA never had access to payment details, Steam passwords, or Steam Guard codes.

Valve is warning affected customers to expect phishing attempts by email, text, or phone that reference their hardware order to appear legitimate, potentially citing the customer's own address. These messages may request a "confirmation," a small delivery or customs fee, or a login to "verify" the order, and Valve says any such messages should be treated as fraudulent. Customers do not need to change their passwords or account settings, since login credentials were not part of the breach.

Valve reiterated standing security guidance: Steam Support only operates through help.steampowered.com and never via email, Steam Chat, or Discord; legitimate Steam pages exist only at store.steampowered.com, www.steampowered.com, steamcommunity.com, or help.steampowered.com, and users should type these addresses manually rather than clicking links; and neither Steam Support nor couriers will ever ask for a password or Steam Guard code.

CEVA has isolated the compromised systems, taken them offline, and brought in external investigators to assist with the response. Sources differ slightly on notification of authorities: one report states CEVA notified data protection authorities after discovering the hack, while another says Valve is in the process of notifying data protection authorities in all affected countries. Valve says it is pushing CEVA for a complete picture of the breach's scope and method.