Valve has disclosed that a cyberattack on CEVA Logistics, its European shipping partner for Steam hardware products like the Steam Deck, Steam Machine, and Steam Controller, has led to the exposure of customer data for buyers across Europe. The breach occurred between July 29 and August 1, 2026, with Valve becoming aware of the incident on August 7. The company has since notified all affected customers via direct security emails.
The compromised data includes customers’ full names, street addresses, postal codes, cities, countries, phone numbers, email addresses associated with their Steam accounts, and details about the hardware purchased, including type and price. Importantly, Valve has clarified that no Steam account credentials, passwords, Steam Guard codes, or payment information were affected, as CEVA does not have access to this sensitive data.
Broader Impact of the CEVA Logistics Breach
This incident is part of a larger cyberattack targeting CEVA Logistics’ European operations. Reports indicate that the attack disrupted eight CEVA warehouses, causing shipping delays for various retail clients. Dutch companies such as e-commerce giant Bol and department store De Bijenkorf have confirmed that customer names, addresses, phone numbers, email addresses, order numbers, and purchased item details were exposed, though payment credentials remained secure.
The breach has also impacted other organizations relying on CEVA for order fulfillment, including football club Ajax, bank ING, and eyewear retailer Ace & Tate. These entities have notified customers and regulatory bodies, including the Dutch Data Protection Authority, about the data exposure.
Notably, this is not CEVA’s first encounter with cyber threats. In September 2025, a group known as CoinbaseCartel claimed responsibility for a separate, more extensive breach of CEVA, alleging the theft of full database schemas containing client accounts, costs, VAT numbers, and financial data. It remains unclear whether the current incident is connected to the previous breach or represents a new intrusion.
Potential Risks and Recommendations for Affected Customers
The exposure of personal information such as real names, home addresses, phone numbers, and specific purchase details creates an environment ripe for sophisticated phishing and delivery-fraud campaigns. With the advancement of generative AI tools, scammers can craft highly personalized and convincing fraudulent messages.
Steam users who have received notifications from Valve should be vigilant for fake delivery, refund, or account-verification emails that reference their actual order details. Any unsolicited communication requesting payment, login credentials, or personal verification should be treated with suspicion. Valve advises customers to verify communications exclusively through official Steam channels and to remain alert for potential scam attempts exploiting the leaked shipping data.
This incident highlights a critical vulnerability in digital supply chains: even when primary vendors like Valve maintain robust internal security measures, third-party logistics partners handling physical fulfillment can become weak links, exposing customer data beyond the breached company’s own systems. It underscores the necessity for companies to ensure that their partners adhere to stringent cybersecurity standards to protect customer information effectively.