News
Valve Warns Steam Hardware Buyers in Europe After Shipping Partner Cyberattack
Valve is emailing Steam hardware customers across Europe to tell them their personal details “was likely compromised” after a cyberattack hit CEVA Logistics, the third-party company that ships Steam Deck, Steam Machine and Steam Controller orders on the continent. The emails began landing on August 10, 2026, and the full text was reproduced by GamingOnLinux, one of the outlets whose staff received it directly.
According to Valve’s email, the attack on CEVA ran from July 29, 2026 to August 1, 2026. CEVA told Valve on August 7, 2026 that customer information had likely been taken. Because CEVA holds delivery data for up to 90 days after an order, Valve says it is contacting every customer it can assume was impacted: anyone who ordered Steam hardware in Europe in roughly the past three months.
The data CEVA receives from Steam is delivery information only, and Valve’s email lists exactly what may have been exposed: name, street address, postal code, city, country, phone number, the email address tied to the customer’s Steam account, and the type and price of the product ordered.
What was not taken
Valve is explicit that the breach stops at shipping data. “CEVA does not have access to your payment information, passwords, Steam Guard codes or other information,” the email states, and customers do not need to change their Steam password or touch their account settings.
The practical risk, as Valve frames it, is targeted phishing built on real order details. The email tells customers to expect fake messages by email, SMS or phone that reference their hardware order and appear to come from Steam, Valve or a delivery company — messages that can quote the victim’s own address back to them, ask them to confirm a delivery, request a small customs or redelivery fee, or push them to sign in somewhere to “verify” an order. Valve’s instruction is to treat all of them as fake, and it notes that Steam Support only ever operates through help.steampowered.com, never by email, Steam Chat or Discord, and never asks for a password or Steam Guard code.
The attack on CEVA’s European warehouses
The Valve disclosure is the second shoe to drop from the CEVA attack. The logistics company, a subsidiary of French shipping group CMA CGM, informed retail customers on August 1, 2026 that a cyber intrusion was disrupting part of its contract-logistics operation, with FreightWaves reporting that eight of its European warehouses were affected. Dutch retailers Bol and De Bijenkorf warned their own customers of a possible data leak through CEVA in the days that followed. Valve’s email confirms the same incident also carried off customer data, and says CEVA has isolated the affected systems, taken them offline and brought in outside investigators.
CEVA is one of the world’s largest third-party logistics providers, operating more than 1,000 warehouses globally. Valve says it is still pressing the company for the full scope of what was taken and how, and that it is notifying data protection authorities in the affected countries — the kind of disclosure European privacy law requires once a company concludes personal data likely left its control.
What happens next
For affected customers, nothing needs to be done to their Steam accounts — Valve’s guidance is vigilance against order-themed scams, not remediation. The open items sit with the two companies: CEVA’s outside investigators have yet to establish the full scope of the intrusion, and Valve’s notifications to national data protection authorities across the affected European countries are in progress. Regulators in those countries can open their own inquiries once notified.
The breach lands in the middle of Valve’s broadest hardware push since the Steam Deck. The company raised the Steam Machine’s price in June 2026, blaming the memory shortage, and has been shipping the Steam Controller alongside it. Its platform work has continued in parallel. A Steam client update earlier in August 2026 patched the startup login dialog and network transfers. Customers awaiting European hardware deliveries through CEVA’s disrupted warehouses may also see knock-on shipping delays while the eight affected sites remain offline.











