TechNewsReel
Live

Valve Alerts European Steam Hardware Customers to Logistics Partner Data Breach

A cyber attack on third-party fulfillment provider CEVA Logistics exposed personal data of European customers who purchased Steam hardware.

TechNewsReel Newsroom · August 11, 2026

Valve has notified customers who purchased Steam hardware in Europe that their personal information was likely compromised in a recent cyber attack. The breach did not occur on Valve's own servers but through a third-party logistics partner.

The security incident took place at CEVA Logistics, the firm responsible for Valve's hardware fulfillment across the European region. CEVA Logistics notified Valve of the attack on August 7, 2026. Following this notification, Valve began emailing affected users to alert them of the potential exposure of their data.

Those at risk are specifically customers who purchased Steam hardware in Europe, including the Steam Machine, Steam Controller, and Steam Deck. While shipping and contact details were exposed, Valve confirmed that core Steam account data—including passwords, payment information, and Steam Guard codes—was not affected by the breach.

The Supply Chain Vulnerability

Valve relies on third-party logistics companies like CEVA Logistics to manage the physical distribution and shipping of hardware. To fulfill these orders, these partners require access to sensitive customer information, such as physical addresses and contact details. This creates a secondary attack vector for cybercriminals, who can target the less secure infrastructure of a partner to obtain personal data without having to penetrate Valve's primary secure servers.

Industry Implications

This incident underscores the persistent risk of "supply chain" vulnerabilities in data security. A company's overall security posture is often only as strong as its least secure partner. Even when a primary company maintains rigorous internal security, the necessity of sharing data with vendors for operational needs creates a gap that attackers frequently exploit.

For the affected users, the exposure of physical addresses and contact information increases the risk of targeted phishing campaigns or identity theft. While the lack of password leaks mitigates the immediate risk of account takeovers, the leak of PII (Personally Identifiable Information) remains a significant privacy concern.

What to Watch

Valve continues to communicate with affected users as the situation unfolds. It remains to be seen if CEVA Logistics will provide further details regarding the scope of the breach or the specific methods used by the attackers. Users are encouraged to remain vigilant against unsolicited communications that may use their leaked shipping details to appear legitimate.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.