Valve is notifying Steam hardware customers in Europe that their personal data was stolen following a cyberattack on its shipping partner, CEVA Logistics. The attack occurred between July 29 and August 1, compromising names, addresses, phone numbers, email addresses, and order details for customers who had hardware shipped to them in Europe. No Steam account credentials, payment information, or passwords were affected, as CEVA does not have access to that data. Valve is warning affected customers to be vigilant against phishing attempts via email, SMS, or phone calls that may use the stolen information to appear legitimate.
Table of contents
Related Articles:Questions this post answers
What data was stolen in the Valve Steam CEVA Logistics data breach?
The stolen data includes affected customers' names, physical addresses, phone numbers, email addresses, and the type and price of ordered products. No Steam account credentials, passwords, Steam Guard codes, or payment information were compromised, as CEVA Logistics does not have access to that data. CEVA retains shipping-related information for up to 90 days after an order, which is why customers from that window were notified. Steam customers tracking this breach can follow developments alongside other security incidents on daily.dev.
When did the CEVA Logistics cyberattack affecting Steam customers happen?
The cyberattack on CEVA Logistics occurred between July 29 and August 1, 2026, disrupting operations at eight of its European warehouses. Valve learned of the breach on August 7 and began notifying affected Steam hardware customers shortly after. CEVA has since isolated the affected systems, taken them offline, and brought in outside investigators. Developers and security professionals keeping up with third-party supply chain incidents find coverage like this on daily.dev.