Steam Hardware Customer Data Breach

Steam Hardware Customer Data Breach

If you bought a Steam Machine, Steam Controller, or Steam Deck in Europe recently, there's some bad news.

Valve confirmed on August 10 that its European shipping partner, CEVA Logistics, suffered a cyberattack between July 29 and August 1, 2026. The company learned about the potential data compromise on August 7 and immediately began notifying affected customers.

CEVA is no small operation. The logistics giant operates 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in revenue in 2025. The attack reportedly disrupted operations at eight warehouses across five European countries.

What information was exposed?

According to Valve's email to customers, the following data was likely compromised:
  • Full name
  • Street address, postal code, and city
  • Phone number
  • Email address (the one linked to your Steam account)
  • Type of product ordered and its price
Here's what wasn't exposed: payment information, passwords, Steam Guard codes, or any data related to other Steam purchases. CEVA only has access to delivery-related information, which is why the breach is limited to shipping data.

What Valve is telling customers

The company's warning is blunt: "Expect fake messages".

Scammers now have enough details—your name, address, and what you ordered—to craft convincing phishing attempts. Valve warns they may:
  • Quote your address to "prove" they're legitimate
  • Ask you to confirm a delivery
  • Request payment for customs or redelivery fees
  • Direct you to a fake login page to "verify" your order
Valve's message is clear: treat all such communications as fake. The company also stressed that Valve support never reaches out via email, Steam Chat, or Discord.

What you should do

  1. Don't change your Steam password — Valve says it's unnecessary
  2. Be skeptical of any unexpected messages about your Steam hardware order
  3. Only trust communications from help.steampowered.com
  4. Report suspicious attempts — Valve is notifying data protection authorities across affected European countries
CEVA has isolated the affected systems and brought in outside investigators. Valve says it's "pressing CEVA for the full scope of what was taken and how".

If you're in the US or outside CEVA's European operating area, you're likely not affected. But if you're in Europe and ordered any Steam hardware in the past three months, stay vigilant.

إرسال تعليق

أحدث أقدم