LIVE · cybersecurity feed
Live wire
data breachmedium

Valve warns Steam hardware buyers: Expect fake delivery scams

Valve has alerted European customers of its Steam hardware that a data breach at its shipping partner, CEVA Logistics, has exposed personal information. The exposed data includes names, addresses, phone numbers, and Steam account emails, along with details of hardware orders. While passwords and payment information were not compromised, the exposed data could be used in sophisticated phishing and delivery scams.

zeroday.news ·

Valve has issued a warning to European customers who recently purchased hardware through its Steam platform, advising them to be vigilant against potential delivery scams following a cyberattack on its shipping partner, CEVA Logistics. The incident, which occurred between July 29 and August 1, 2026, exposed personal information including names, home addresses, phone numbers, Steam email addresses, and details of hardware orders.

Valve confirmed it was notified of the breach on August 7 and began notifying affected customers on August 10. The company emphasized that its own systems were not compromised and that customer passwords and payment information remain secure. The breach specifically affected data held by CEVA Logistics, which handles deliveries for Steam hardware in Europe.

CEVA Logistics typically retains delivery data for approximately 90 days post-shipment. This means any customer in Europe who received a Steam Deck, Steam Controller, or Steam Machine within the last three months could be impacted. The exposed data includes the customer's name, street address, postal code, city, country, phone number, the email address linked to their Steam account, and specifics about the ordered hardware, such as type and price. The exact number of affected customer records has not been disclosed by either Valve or CEVA.

Reports indicate that Dutch retailers Bol and De Bijenkorf were also informed of the same CEVA incident on August 1 and subsequently alerted their customers.

The primary concern stemming from this data exposure is the potential for highly convincing phishing attempts. Scammers can leverage the stolen information to craft emails, text messages, or even phone calls that accurately reference a customer's genuine order and delivery address. These fraudulent communications might then request a small customs or redelivery fee, ask for confirmation of delivery, or prompt the user to sign in to verify their order, all designed to trick recipients into divulging further sensitive information or clicking malicious links.

Valve's advice to customers is to treat any unsolicited message concerning a recent Steam hardware order as potentially fraudulent, regardless of how accurate the details appear. The company reiterated that Steam Support communicates with users only through its official help page and never via email, Steam Chat, or Discord. While a password reset is not immediately necessary due to the nature of the breach, Valve recommends maintaining strong, unique passwords and enabling Steam Guard's two-factor authentication.

This incident is not Valve's first encounter with security challenges. In May 2025, a threat actor attempted to sell a dataset purportedly containing 89 million Steam user records, which Valve later clarified were older SMS messages with expired two-factor codes routed through an unpartnered third party. A more direct breach occurred in November 2011, exposing records from 35 million users, including usernames, emails, and encrypted credit card details.

data breachphishingsteamvalveshipping partner
ShareXLinkedInWhatsAppFacebook

More News

view all →
cloud

Fortune 500 Companies Hit in Azure Data Theft Campaign

A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations. The post Fortune 500 Companies Hit in Azure Data Theft Campaign appeared first on SecurityWeek.

security

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. A chip that never checks who’s asking The attack, named “Download More RAM,” targets a small configuration chi

ai

Hazmat: Open-source containment for AI agents

Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configura

nation-state

Product showcase: ScamNet looks for warning signs in suspicious calls and shady links

ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and Mac, with features varying by platform. Call protection is available on iPhone, while tools such as Visual Intelligence are supported on iPhone and iPad. The a

vulnerability

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service

breach

Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI

PLUS: HCL, TCS, admit data breaches; Google, Apple, India bans some rideshare tips; and more!