Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: ceva-logistics (1 article)Clear

Valve warns Steam hardware buyers of data breach at its shipping partner

Valve is notifying European Steam hardware customers that their personal data was likely exposed in a cyberattack on CEVA Logistics, the partner that ships Steam devices in the region. Attackers had access to CEVA systems between July 29 and August 1, reaching the delivery details CEVA keeps for up to ninety days: name, street address, postal code, city, country, phone number, the email tied to the Steam account, and the hardware ordered and its price. No Steam passwords, Steam Guard codes, or payment data were exposed, since CEVA never held them. Valve warned customers to expect phishing and delivery-impersonation scams and to treat such messages as fake.

Check
If you ordered Steam hardware in Europe recently, expect phishing by email, text, or phone impersonating Valve or a courier, and treat requests for fees, signatures, or confirmations as fraudulent.
Affected
European Steam hardware customers whose name, address, phone number, email, and order details were exposed through the CEVA breach; no passwords or payment data were affected, but the data enables convincing scams.
Fix
No need to change your Steam password, but stay alert to delivery-themed phishing, verify courier requests through official channels, and hold logistics vendors to the same breach standards as internal systems.