Valve says a cyberattack on shipping partner CEVA Logistics exposed data for some Steam hardware customers in Europe. Valve says attackers had access to CEVA servers between July 29 and August 1, 2026 and likely stole delivery-related records retained for up to 90 days, including names, addresses, phone numbers, email addresses, and the type and price of ordered products; CEVA did not have payment card data, Steam passwords, or Steam Guard codes.
Why it matters: Affected customers face a credible risk of convincing phishing, smishing, and vishing that uses real order and address details. Users should be wary of delivery, customs-fee, or account-verification messages claiming to be from Steam, Valve, or carriers, even if the sender knows their order information.
Lawrence Abrams
2026.08.17
92% relevant
This article adds another confirmed downstream victim of the same CEVA Logistics cyberattack in Europe, showing that Pokémon Center customers in the UK and Germany had names, addresses, phone numbers, email addresses, and order contents exposed, and that some orders were canceled in addition to shipment delays.
Ionut Arghire
2026.08.12
89% relevant
This article appears to cover the same CEVA Logistics incident and adds broader operational context: the attack disrupted eight European warehouses starting July 29, delayed shipments for multiple customers, and affected organizations beyond Valve including Bol, De Bijenkorf, ING, Ace & Tate, and Ajax.
2026.08.11
96% relevant
This article adds broader context to the same CEVA intrusion by tying it to disrupted operations at eight European warehouses and naming additional affected customers including Bol, De Bijenkorf, Ace & Tate, and Ajax, while reinforcing that Steam hardware buyer data may have been exposed through CEVA’s order-processing systems.
Sergiu Gatlan
2026.08.10
100% relevant
This article establishes a distinct breach event: Valve is notifying affected customers after a compromise at CEVA Logistics exposed Steam hardware shipment data.
← Back to all stories