Valve warns European Steam hardware buyers after shipping partner data breach
Valve has started warning some European customers that their personal delivery information may have been exposed after a cyberattack hit CEVA Logistics, the company’s shipping partner for Steam hardware orders in the region.
The incident affected CEVA Logistics systems between July 29 and August 1, 2026. Valve says it became aware of the likely data compromise on August 7 and has since begun notifying customers who may have been impacted.
The breach is tied to Steam hardware shipments in Europe, including orders for devices such as Steam Deck units, Steam Controllers, and Steam Machines. CEVA Logistics, which handles deliveries for Valve across parts of Europe, stores shipping-related customer information for a limited period after an order is placed. According to Valve, that retention period can last up to 90 days, meaning customers who purchased Steam hardware in Europe during that window could potentially be affected.
The information believed to have been exposed includes customer names, delivery addresses, countries, phone numbers, Steam account email addresses, and details about the hardware purchased. Valve emphasized that sensitive account and payment data was not stored by CEVA Logistics and was not included in the breach. This means Steam passwords, Steam Guard codes, and payment information were not part of the exposed data.
Even so, the stolen delivery details could still be useful to scammers. Valve is warning affected customers to be on alert for phishing attempts by email, text message, or phone call. Fraudsters may pretend to be from Steam, Valve, CEVA Logistics, or another delivery company and may refer to a real hardware order to make the message seem legitimate.
Customers should be especially cautious of messages claiming that an order requires a customs fee, redelivery payment, address confirmation, or account login verification. Valve warned that scammers may even quote a customer’s real address or hardware purchase details to build trust before trying to steal money or account credentials.
Valve says customers should treat any unexpected request for payment or login details related to their Steam hardware order as suspicious. Legitimate companies will not ask users to share Steam passwords, Steam Guard codes, or payment details through unsolicited messages.
CEVA Logistics has said it is continuing to investigate the incident and has isolated the affected systems. The company is a major global logistics provider, operating across many countries and serving a wide range of retail and technology clients. Reports indicate that the cyberattack affected multiple warehouse hubs and contributed to shipping delays for several European retail customers.
Valve says it is pushing CEVA Logistics for more information about how the attack happened, what systems were accessed, and the full scope of the data taken. The company also plans to notify the relevant data protection authorities in affected European countries as the investigation continues.
At this stage, Valve has not confirmed how many Steam customers were impacted. The company’s warnings appear focused on European customers who purchased Steam hardware and whose shipping information may still have been stored by CEVA Logistics at the time of the breach.
For Steam users who recently ordered hardware in Europe, the safest approach is to be cautious with any message related to delivery, customs, refunds, or order verification. Customers should avoid clicking suspicious links, should not provide login codes or passwords, and should verify delivery issues through official account pages or trusted customer support channels.
While Valve says Steam accounts and payment information were not compromised, the exposure of names, addresses, phone numbers, email addresses, and order details creates a real risk of targeted scams. Anyone who receives a message referencing a recent Steam Deck or other Steam hardware purchase should carefully check the sender and assume that urgent payment requests may be fraudulent.
The investigation remains ongoing, and further details may emerge as Valve and CEVA Logistics determine the full impact of the breach.






