CEVA Logistics Data Breach Exposes Valve Steam Hardware Buyers’ Information
Key Takeaways Valve confirmed a data breach at its European shipping partner, CEVA Logistics, impacting customers who purchased Steam hardware. The breach exposed personal and order details,...
Key Takeaways
- Valve confirmed a data breach at its European shipping partner, CEVA Logistics, impacting customers who purchased Steam hardware.
- The breach exposed personal and order details, including names, addresses, phone numbers, email addresses, and specific hardware purchased.
- No Steam account credentials, passwords, or payment information were compromised, as CEVA Logistics did not store this data.
- The incident, which occurred between July 29 and August 1, 2026, has also affected other major European retailers and highlights supply chain security risks.
- Affected users should be vigilant against sophisticated phishing and delivery fraud attempts leveraging their exposed information.
CEVA Logistics Cyberattack Exposes Steam Hardware Buyers’ Data
Valve has officially confirmed that a recent cyberattack targeting CEVA Logistics, its primary European shipping provider for hardware like the Steam Deck, Steam Machine, and Steam Controller, resulted in the exposure of customer data belonging to buyers across the continent.
Table Of Content
The security incident took place between July 29 and August 1, 2026. Valve became aware of the compromise on August 7 and subsequently initiated direct security email notifications to all customers believed to be impacted.
Details of the Data Exposure
According to Valve’s disclosure, the attackers likely gained access to delivery-related information maintained by CEVA Logistics for a period of up to ninety days post-order. This sensitive data includes customers’ full names, street addresses, postal codes, cities, countries, phone numbers, the email addresses linked to their Steam accounts, and detailed information regarding the type and price of the hardware ordered.
Crucially, Valve emphasized that no Steam account credentials, passwords, Steam Guard codes, or payment information were affected. This is because CEVA Logistics does not have access to such data in the first place, maintaining a clear separation of financial and account security from logistics operations.
Broader Impact of the CEVA Logistics Breach
The Valve notification is part of a more extensive cyber incident that has significantly impacted CEVA Logistics’ European operations. Reports from FreightWaves indicate that the attack disrupted eight CEVA warehouses, leading to shipping delays for numerous retail clients. Affected customers were first alerted to the intrusion on August 1.
Beyond Valve, major European entities have also confirmed exposure. Dutch e-commerce giant Bol and department store De Bijenkorf both reported that customer names, addresses, phone numbers, email addresses, order numbers, and details of purchased items were compromised, though payment credentials remained secure. The ripple effect has extended to include football club Ajax, bank ING, and eyewear retailer Ace & Tate, all of whom utilize CEVA for order fulfillment. These organizations have separately notified their customers and relevant regulators, including the Dutch Data Protection Authority.
Past Incidents and Future Risks
This is not CEVA Logistics’ first encounter with cyber adversaries. In September 2025, a threat group identified as CoinbaseCartel claimed responsibility for a separate, more extensive breach of CEVA, allegedly exfiltrating comprehensive database schemas encompassing client accounts, costs, VAT numbers, and financial data. At present, it remains unconfirmed whether the current incident is linked to this earlier compromise or represents an entirely new intrusion.
Security researchers are sounding alarms over the combined exposure of real names, home addresses, phone numbers, and specific purchase details. This data combination creates fertile ground for highly convincing phishing and delivery-fraud campaigns, a risk amplified by the ease with which generative AI tools can now personalize scam messages. Valve has advised customers to verify all communications exclusively through official Steam channels and to remain highly vigilant for follow-up scam attempts that exploit the leaked shipping information.
The incident serves as a stark reminder of the inherent vulnerabilities within digital supply chains. Even when a primary vendor like Valve maintains robust internal security protocols, third-party logistics partners responsible for physical fulfillment can inadvertently become the weakest link, exposing sensitive customer data far beyond the initial company’s direct control.
What You Should Do
- Be Skeptical of Unsolicited Communications: Treat any unexpected emails, SMS messages, or phone calls claiming to be from Steam, Valve, or CEVA Logistics with extreme caution.
- Verify Through Official Channels: If you receive a suspicious message regarding a Steam hardware order, do not click on any links. Instead, navigate directly to the official Steam website or app to check your order status or account notifications.
- Never Share Credentials or Codes: Steam will never ask for your password, Steam Guard codes, or payment information via email or phone. Be wary of any request for this sensitive data.
- Watch for Phishing and Delivery Scams: Expect an increase in sophisticated phishing attempts that may reference your actual order details. These could include fake delivery notifications, refund offers, or account verification requests designed to steal your information.
- Monitor Your Accounts: Regularly review your Steam account activity and any linked email accounts for unusual behavior.
- Consider Identity Theft Protection: Given the breadth of personal information exposed, consider enrolling in identity theft protection services if you are concerned about broader misuse of your data.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.