TechNewsReel
Live

Cyberattack on CEVA Logistics Exposes European Steam Hardware Customer Data

A breach at a third-party shipping partner leaked personal details of Valve hardware buyers, though core Steam account security remains intact.

TechNewsReel Newsroom · August 13, 2026

A cyberattack on CEVA Logistics, a European shipping partner for Valve, exposed the personal information of thousands of Steam hardware customers. The breach targeted operational databases across eight European facilities between July 29 and August 1, 2026.

Compromised data includes full names, physical shipping addresses, phone numbers, and Steam-linked email addresses. Attackers also accessed specific hardware order details, including the type of item purchased and the price paid. Valve began notifying affected European customers on August 10, 2026, warning them of the potential for targeted spear-phishing attacks.

Infrastructure and Scope

The breach occurred exclusively at CEVA Logistics and did not penetrate Valve's own servers or Steam's core infrastructure. The incident affected customers who had physical Valve hardware—such as the Steam Deck, Steam Machine, or Steam Controller—delivered within Europe during a 90-day window prior to the attack.

Valve's use of a microservice architecture limited the damage. By restricting the data shared with third-party logistics (3PL) providers to the minimum required for delivery, the company prevented attackers from accessing core Steam account databases. Consequently, sensitive information including Steam passwords, payment card information (PCI), Steam Guard codes, and account authentication tokens were not compromised.

The Risk of Targeted Phishing

While core account security remains secure, the leak of high-fidelity shipping data creates a significant security risk for affected users. The availability of exact order details and physical addresses allows bad actors to launch highly convincing spear-phishing and smishing campaigns.

Industry analysts warn that attackers can use this specific data to impersonate couriers or Valve support staff. By referencing a real order and a correct home address, scammers can trick users into paying fraudulent customs fees or revealing account credentials through social engineering.

Next Steps for Users

Valve advises affected users to remain vigilant against unsolicited communications. Because the breach was limited to the logistics partner, users are not required to change their Steam passwords, but they should be wary of any emails or texts requesting payment or login details related to their hardware shipments. Monitoring for unusual activity and verifying the authenticity of courier communications remains the primary defense for those in the affected European regions.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.