Valve notifies Steam hardware customers of a data breach

Steam Hardware Customers Hit by Data Breach After CEVA Logistics Hacking

Valve, the company behind the popular digital distribution platform Steam, is notifying its hardware customers in Europe that their data has been stolen following a hacking incident at its shipping partner, CEVA Logistics. The breach has exposed sensitive information, including names, addresses, phone numbers, and email addresses of affected individuals.

CEVA Logistics is one of the world’s largest logistics companies, with over 1,000 warehouses and 15 million shipments handled last year alone. It was informed that a cyberattack had disrupted operations at eight of its European warehouses on August 1. Valve has since confirmed that the attackers had access to CEVA’s servers between July 29 and August 1, allowing them to gain sensitive information needed for shipping hardware orders.

The stolen data includes details such as the type and price of ordered products, but fortunately, no additional information related to Steam accounts or other purchases was compromised. This is because CEVA does not have access to payment information, passwords, Steam Guard codes, or other sensitive data.

Valve has warned affected customers that they may be targeted by phishing messages using the stolen information to impersonate Steam, Valve, or delivery companies. These emails or calls may quote the customer’s address back to them as a way of proving legitimacy. “They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to ‘verify’ your order,” Valve cautioned. “Treat all of them as fake.”

In response to the breach, Valve is working closely with CEVA Logistics to determine the full scope of what was stolen and how it happened. The company has also notified data protection authorities in affected countries, including those in Europe. As a precautionary measure, customers are advised to remain vigilant and be cautious of any suspicious emails or calls.

For Steam users, this incident serves as a reminder of the importance of staying informed about potential security threats. Valve’s response to the breach demonstrates its commitment to protecting customer data and ensuring that affected individuals receive timely notification.

In light of this incident, it is essential for users to remain vigilant and take steps to protect themselves from potential phishing attacks. This includes being cautious when receiving unsolicited emails or calls requesting sensitive information. By taking proactive measures, customers can minimize their risk exposure and ensure the security of their personal data.


Source: Bleeping Computer — 2026-08-10