Valve has notified Steam hardware customers in Europe that their personal and order information was stolen by hackers who broke into the shipping partner CEVA Logistics’ servers. The breach occurred between July 29 and August 1, with attackers gaining access to details such as names, addresses, phone numbers, email addresses, and product orders.
CEVA Logistics is a massive logistics company operating 1,000 warehouses across the globe and handling over 15 million shipments annually. Its European operations were targeted by hackers, who likely used this information to ship counterfeit or malicious goods to customers. Valve, the popular video game publisher behind Steam, has confirmed that no sensitive data, such as payment information, passwords, or Steam Guard codes, was compromised.
The stolen data may be used for phishing attacks targeting affected individuals. These scams typically involve emails, SMS messages, or voice calls claiming to be from a legitimate source, such as Steam or a delivery company. The attackers often quote the victim’s address to appear genuine and ask them to confirm a delivery or pay a small fee. Valve has warned customers not to engage with these suspicious communications and assured them that they don’t need to change their Steam password or account settings.
Valve is working closely with CEVA Logistics to investigate the breach, isolate affected systems, and notify local data protection authorities in Europe. The company has also taken steps to secure its shipping processes and prevent similar incidents in the future. While Valve has informed customers about the breach, it’s essential for individuals to remain vigilant and report any suspicious activity to Steam’s support team.
The incident highlights the importance of security measures beyond just protecting internal networks. Companies like CEVA Logistics often have vast amounts of sensitive data flowing through their systems, making them attractive targets for hackers. By prioritizing robust cybersecurity practices and conducting regular vulnerability assessments, organizations can minimize the risk of breaches and protect their customers’ personal information.
For Steam hardware customers affected by this breach, it’s crucial to be cautious when receiving unsolicited emails or messages claiming to be from delivery companies or online services. Remember that legitimate companies will never ask you to confirm sensitive information via email or phone. Stay informed about security updates from Valve and other relevant sources, and always report any suspicious activity to the authorities.
Source: Bleeping Computer — 2026-08-10