Valve has confirmed that a cyberattack on its logistics partner, CEVA Logistics, between July 29 and August 1, 2026, has likely compromised personal data of Steam customers in Europe who purchased hardware. The company is urging affected users to be vigilant against phishing attempts that may reference their orders.
What Data Was Compromised?
In an email sent to affected customers on August 10, 2026, Valve stated that the attack targeted CEVA Logistics, the shipping company responsible for delivering Steam Machines and Steam Controllers. The investigation is ongoing, but Valve warned that 'information about Steam customers' was 'likely compromised.' The potentially exposed data includes names, street addresses, country, phone numbers, email addresses, and details of ordered products. However, Valve assured that passwords, payment information, and Steam Guard codes were not affected, as CEVA does not have access to such data.
Valve's Warning and Advice
Valve cautioned customers to 'expect fake messages' via email, text, or phone that might reference their hardware order and appear to come from Steam, Valve, or a delivery company. The company warned that scammers may quote the customer's address to seem legitimate and could ask for delivery confirmation, payment of customs fees, or login to verify orders. Valve emphasized, 'Treat all of them as fake.'
Ongoing Investigation and Regulatory Notifications
Valve is 'pressing CEVA for the full scope of what was taken and how,' and CEVA is in the process of notifying data protection authorities in affected countries. This incident comes amid the recent rollout of Steam Machines and Steam Controllers, which have been shipping to pre-order customers over the past few months.
Previous Security Concerns
Last year, Valve faced reports of a Steam data leak, but the company downplayed the breach, stating it only involved old text messages. The current situation underscores ongoing cybersecurity challenges in the gaming hardware supply chain.



