Tue 11 Aug 2026 / 16:43 ET
Kernel
Internet 2 min read

Steam hardware data breach exposes European shipping details

Valve says a breach at CEVA Logistics likely exposed delivery and order data for European Steam hardware customers.

June Castellano

By June Castellano / Platforms & Power Reporter

Steam hardware data breach exposes European shipping details
img: The Verge

The steam hardware data breach involves CEVA Logistics, the company Valve uses to deliver Steam hardware in Europe. Valve has told customers that a cyberattack at the shipper likely exposed delivery and purchase information, creating unusually credible material for impersonation scams.

According to reports on Valve’s customer notice, the intrusion occurred from July 29 through August 1, 2026. Valve learned on August 7 that customer data was likely compromised and began alerting customers on August 10. The company has not disclosed how many people may be affected.

The scope is European customers who ordered physical Steam hardware. CEVA retains delivery records for as long as 90 days after an order, so Valve is notifying people whose information may have been held during that period. That is a precautionary group, not a confirmed list of victims.

What data did the Steam hardware breach expose?

Valve said the potentially exposed information includes a customer’s name; street address, postal code, city and country; phone number; and the email address associated with the person’s Steam account. The records may also include the type and price of the Steam hardware ordered.

That combination is enough to build a persuasive scam. A fraudulent text, email or call can cite a real order and home address, then pose as Steam, Valve or a delivery company. Valve warned that messages may seek a delivery confirmation, a small customs or redelivery payment, or a sign-in supposedly needed to verify an order.

Valve said CEVA did not hold customers’ payment information, Steam passwords or Steam Guard codes. The company also said other Steam account information and unrelated purchases were not affected. Based on that scope, Valve did not advise affected customers to change their password or account settings because of this incident.

What should affected customers do?

Valve’s instruction is blunt: treat unsolicited contacts about a Steam hardware order as fraudulent, even if the sender knows an address or purchase detail. Account issues should be handled through help.steampowered.com rather than links in messages, Steam chat, Discord, email, SMS or a cold call. Customers should not provide a Steam password or Steam Guard code to a purported support agent or courier.

CEVA has isolated the systems involved, taken them offline and hired outside investigators, according to reports of Valve’s notice. Valve said it is seeking more information about the data taken and the cause of the incident, while notifying data-protection authorities in the affected countries. The investigation remains incomplete, so the company’s description is still “likely compromised,” rather than a final accounting of what attackers obtained.

This story draws on original reporting from The Verge.

More Internet/

view all ↗