Valve has issued a warning to European customers who recently purchased hardware through its Steam platform, advising them to be vigilant against potential delivery scams following a cyberattack on its shipping partner, CEVA Logistics. The incident, which occurred between July 29 and August 1, 2026, exposed personal information including names, home addresses, phone numbers, Steam email addresses, and details of hardware orders.
Valve confirmed it was notified of the breach on August 7 and began notifying affected customers on August 10. The company emphasized that its own systems were not compromised and that customer passwords and payment information remain secure. The breach specifically affected data held by CEVA Logistics, which handles deliveries for Steam hardware in Europe.
CEVA Logistics typically retains delivery data for approximately 90 days post-shipment. This means any customer in Europe who received a Steam Deck, Steam Controller, or Steam Machine within the last three months could be impacted. The exposed data includes the customer's name, street address, postal code, city, country, phone number, the email address linked to their Steam account, and specifics about the ordered hardware, such as type and price. The exact number of affected customer records has not been disclosed by either Valve or CEVA.
Reports indicate that Dutch retailers Bol and De Bijenkorf were also informed of the same CEVA incident on August 1 and subsequently alerted their customers.
The primary concern stemming from this data exposure is the potential for highly convincing phishing attempts. Scammers can leverage the stolen information to craft emails, text messages, or even phone calls that accurately reference a customer's genuine order and delivery address. These fraudulent communications might then request a small customs or redelivery fee, ask for confirmation of delivery, or prompt the user to sign in to verify their order, all designed to trick recipients into divulging further sensitive information or clicking malicious links.
Valve's advice to customers is to treat any unsolicited message concerning a recent Steam hardware order as potentially fraudulent, regardless of how accurate the details appear. The company reiterated that Steam Support communicates with users only through its official help page and never via email, Steam Chat, or Discord. While a password reset is not immediately necessary due to the nature of the breach, Valve recommends maintaining strong, unique passwords and enabling Steam Guard's two-factor authentication.
This incident is not Valve's first encounter with security challenges. In May 2025, a threat actor attempted to sell a dataset purportedly containing 89 million Steam user records, which Valve later clarified were older SMS messages with expired two-factor codes routed through an unpartnered third party. A more direct breach occurred in November 2011, exposing records from 35 million users, including usernames, emails, and encrypted credit card details.






