Valve tells European Steam customers their delivery details were stolen in CEVA Logistics hack

The gaming giant says names, addresses and phone numbers were taken after attackers spent four days inside its European shipping partner's systems.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Valve is emailing European customers who bought Steam hardware after its shipping partner CEVA Logistics was hacked between 29 July and 1 August.
  • Stolen data includes names, home addresses, phone numbers, email addresses, and the type and price of the item ordered.
  • No passwords, payment cards, or Steam Guard codes were taken, because CEVA never held that information.
  • Valve was told about the breach on 7 August and is warning customers to expect scam emails, texts and calls that quote their real address.
  • CEVA had already told European retailers on 1 August that a cyberattack had disrupted eight of its warehouses.

Valve, the company behind the Steam games store and the Steam Deck handheld, has started warning European customers that their personal details were stolen when hackers broke into the systems of its shipping partner, CEVA Logistics.

CEVA is a big freight and warehousing firm owned by the French shipping group CMA CGM. It runs around 1,000 warehouses worldwide and moved 15 million shipments last year. Valve uses it to deliver physical Steam hardware, like the Steam Deck, to buyers across Europe.

The notification emails, first reported by BleepingComputer, went out today.

What did the hackers actually take?

The attackers took the information CEVA needed to put a parcel on a doorstep: full name, delivery address, phone number, email address, and the product name and price. Nothing from the Steam account itself was touched.

Valve says CEVA never had access to payment card numbers, Steam passwords, or Steam Guard codes (the one-time codes Steam sends to confirm a login). So the account itself is not at risk from this breach. What is at risk is the customer's inbox and phone.

Detail What Valve says
Attacker access window 29 July to 1 August 2026
Valve informed by CEVA 7 August 2026
Data taken Name, address, phone, email, product, price
Data not taken Passwords, payments, Steam Guard codes
Retention window Up to 90 days of orders

Because CEVA keeps this delivery information for up to 90 days, Valve is emailing every customer whose order fell inside that window.

Should Steam customers be worried?

They should be alert, not alarmed. The main danger now is scams that use the stolen details to sound convincing.

Valve is warning customers to expect phishing attempts, meaning fake emails, texts or calls designed to trick you into paying money or handing over a password. The scammers may read your real address back to you to prove they are genuine, then ask you to pay a small customs charge, confirm a delivery, or sign in to "verify" your order.

Valve's advice is blunt: treat all of it as fake. Do not click links in unexpected delivery messages. There is no need to change your Steam password or touch your account settings, because the Steam account itself was not part of the breach.

How did the hackers get into CEVA?

CEVA has not said. The company is still investigating with outside experts and has taken the affected systems offline.

On 1 August, CEVA told several European retailers that a cyberattack had disrupted operations at eight of its European warehouses. That is the same date the attackers lost access according to Valve's timeline, which suggests CEVA detected the intrusion and cut them off. Valve says it is now pressing CEVA for a full account of what was taken and how, and is notifying data protection regulators in each affected country.

No ransomware group has publicly claimed the attack. There is no word yet on whether a ransom was demanded or paid.

This is the second time in recent years that a Valve customer breach has come through a supplier rather than Valve's own systems, a reminder that the weakest link in a company's security is often a partner who holds a copy of the customer list.

© 2026 Threat Vectr