Valve Warns European Steam Hardware Buyers After CEVA Cyberattack Exposes Customer Data
Valve has warned Steam hardware customers across Europe that personal information associated with recent purchases may have been exposed following a cyberattack against CEVA Logistics, the third party logistics company responsible for shipping Valve hardware throughout the region. According to a report, the attack affected CEVA systems between July 29 and August 1, 2026, with Valve learning on August 7 that customer information was likely compromised.
The incident is particularly relevant as Valve expands its hardware ecosystem across Europe. The company has been shipping products such as the new Steam Controller and Steam Machine, with the latter currently moving through its reservation and purchase invitation system. Valve recently added AMD FSR 4.1 support to Steam Machine, while the new Steam Controller experienced extremely strong demand following its launch earlier this year.
Because CEVA requires customer information to complete deliveries, attackers may have accessed names, street addresses, postal codes, cities, countries, telephone numbers, email addresses associated with Steam accounts, and information identifying the type and price of hardware purchased. Valve says the affected information is limited to hardware orders processed within approximately the previous 90 days, which corresponds with CEVA's data retention period.
Importantly, Valve says the incident did not compromise Steam account credentials or payment information. CEVA did not have access to customer payment details, Steam passwords, Steam Guard authentication codes, or other Steam account information. Valve therefore says affected customers do not need to change their Steam password or modify their account settings specifically because of this incident.
The larger concern is targeted phishing. Attackers possessing a customer's name, address, telephone number, email address, purchased hardware, and its price could create considerably more convincing fraudulent messages. A fake delivery notification could reference the exact Steam product purchased or even include the customer's address before requesting a delivery confirmation, customs payment, login, or other sensitive information. Valve is warning users to treat messages requesting this type of action as fraudulent.
Valve also reiterated that legitimate Steam Support assistance is provided through its official support website and that representatives will never request a Steam password or Steam Guard authentication code. Official Steam services are operated through the Steam Store, Steam Community, Steam Support, and Steam's official website, making it important for users to verify the destination before entering credentials, particularly following a data exposure that could enable more personalized social engineering attempts.
CEVA has reportedly isolated the affected systems and taken them offline while external cybersecurity investigators examine the incident. Valve is also seeking additional information from its logistics partner to determine the complete scope and method of the attack and says it is notifying relevant data protection authorities across affected European countries.
This does not appear to be a compromise of Steam itself, but the type of information exposed still creates a meaningful security risk. Login credentials are obviously more immediately dangerous, yet shipping information combined with a customer's exact hardware purchase gives attackers valuable context for highly convincing phishing and social engineering campaigns.
The timing also matters for Valve. The company is in the middle of its largest hardware expansion since Steam Deck, with Steam Machine, Steam Controller, and Steam Frame forming a much broader SteamOS ecosystem. As Valve increases direct hardware distribution, security across logistics providers becomes part of the customer experience. A compromised shipping partner can create reputational and security consequences even when Valve's own infrastructure remains unaffected.
If you recently purchased Steam hardware in Europe, have you received Valve's security notification, and do incidents like this make you more cautious about ordering hardware directly through digital platforms?
