Valve Warns Steam Hardware Customers After CEVA Logistics Data Breach
A cyberattack on a major shipping partner exposed personal details of European customers who purchased physical Steam hardware.
Valve has notified Steam hardware customers in Europe that their personal information was compromised following a cyberattack on its shipping partner, CEVA Logistics. The breach underscores the persistent security risks inherent in third-party supply chain dependencies.
The security incident occurred between July 29 and August 1, 2026, at CEVA Logistics, a subsidiary of the CMA CGM Group. According to Valve, the breach affected customers who ordered physical hardware within a 90-day window. The stolen data includes names, physical addresses, phone numbers, and email addresses, as well as specific details regarding the type and price of the products ordered.
Valve confirmed that sensitive account credentials remained secure, stating that passwords, payment information, and Steam Guard codes were not accessed during the incident. However, the exposure of shipping and order details provides attackers with a high degree of specificity for future targeting.
The Logistics Vulnerability
CEVA Logistics is one of the world's largest shipping firms, reporting $18.3 billion in revenues in 2025 and operating 1,000 warehouses globally. The scale of the operation means a single point of failure can have wide-reaching consequences. On August 1, the attack disrupted operations at eight of the company's European warehouses, triggering notifications for multiple European retailers.
This incident highlights a critical vulnerability in the hardware supply chain. While a company like Valve may maintain rigorous internal security for its digital platform, the physical delivery of goods requires trusting third-party logistics providers who may have different security postures. When a logistics provider is breached, the personal data of customers from multiple high-profile brands is exposed simultaneously.
The Risk of Targeted Phishing
The specific nature of the stolen data—combining a user's home address with the exact device they purchased—creates a significant risk for sophisticated phishing attacks. Security experts warn that this allows scammers to bypass traditional red flags by borrowing the legitimacy of the real brand.
"When a scammer can quote your real address and reference the exact device you bought, they borrow the legitimacy of the real brand and bypass the mental shortcuts we rely on to spot a fake," said Anna Collard, CISO advisor and SVP of content strategy at KnowBe4.
Valve warned affected users in notification emails that attackers may quote their addresses to prove they are genuine or ask for small customs and redelivery fees. Valve urged customers to treat all such communications as fake.
What's Next
Users who received notifications from Valve should remain vigilant against "smishing" (SMS phishing) and "vishing" (voice phishing) attempts. While the immediate operational disruptions at CEVA Logistics' warehouses have been noted, the long-term impact on customer data privacy remains a primary concern for those affected by the July breach.