Valve Shipping Data Exposed in CEVA Logistics Cyberattack
Personal information of European Steam hardware buyers leaked via third-party logistics partner.
Valve has notified European customers that their personal shipping information was compromised following a cyberattack on CEVA Logistics, a third-party logistics partner. The breach exposed the private details of users who purchased specific Steam hardware, prompting the company to warn its community about potential security risks.
The cyberattack targeted eight European warehouses operated by CEVA Logistics over the weekend of August 1. The leaked data includes the names, physical addresses, and phone numbers of customers. The exposure specifically affected those who purchased Steam hardware, with the Steam Machine and Steam Controller explicitly mentioned as impacted products. Valve clarified that the breach was limited to shipping data; payment information, account passwords, and Steam Guard codes were not affected.
The Scope of the Breach
CEVA Logistics is a global logistics provider operating over 1,000 warehouses and generating approximately $18.3 billion in revenue. While the company noted that the breach was confined to specific warehouse IT systems and did not disrupt broader transportation management services, the impact on retail partners was significant. Valve was not the only company affected; other major retailers, including the Dutch department store De Bijenkorf and the e-commerce giant bol, also saw customer data exposed through the same incident.
Supply Chain Vulnerabilities
This incident underscores the systemic risk inherent in modern supply chain management. Even when a primary company like Valve maintains secure internal systems, its data remains vulnerable if a third-party vendor with lower security standards is compromised. This "weakest link" phenomenon allows attackers to bypass a primary target's defenses by targeting a partner with privileged access to customer personally identifiable information (PII).
While the lack of financial data theft prevents immediate monetary loss, the leak of addresses and phone numbers creates a long-term security liability. This specific type of data is highly valuable for social engineering, as it allows bad actors to craft convincing phishing attempts. By referencing a real purchase and a home address, scammers can more easily deceive users into revealing passwords or installing malware.
Next Steps for Users
Valve has urged affected users to remain vigilant against potential scams and phishing attempts. Because the leaked data is static—meaning addresses and phone numbers cannot be "reset" like a password—users should be particularly skeptical of unsolicited communications that reference their Steam hardware purchases. The industry continues to monitor the fallout from the CEVA breach to determine if further retail partners were impacted by the warehouse system compromise.