Valve's European Shipping Partner, CEVA Logistics, Suffers Cyberattack, Exposing Steam Hardware Customer Data
Video game giant **Valve** is alerting its European **Steam** hardware customers about a data breach at its shipping partner, **CEVA Logistics**. The cyberattack, which occurred between July 29 and August 1, 2026, compromised personal information necessary for shipping, including names, addresses, and product details.
Digital distribution giant **Valve** has begun notifying **Steam** hardware customers in Europe that their personal data was compromised following a cyberattack on its shipping partner, **CEVA Logistics**.
**CEVA Logistics**, a wholly-owned subsidiary of the **CMA CGM Group**, is a massive global logistics provider, managing 1,000 warehouses and 15 million shipments annually. The breach at such a significant entity underscores the far-reaching implications of supply chain vulnerabilities.
Reports circulating on social media indicate that affected **Valve** customers started receiving data breach notification emails earlier today.
**Valve**'s communication detailed that attackers had access to **CEVA Logistics**' servers from July 29 to August 1, 2026. This window allowed them to obtain information critical for fulfilling hardware orders.
"Between July 29 2026 and August 1, 2026, a cyberattack hit **CEVA Logistics**, the company that ships **Steam** hardware to customers in Europe. **CEVA** is still investigating this attack, but as **Valve** learned on August 7, certain information about **Steam** customers, including you, was likely compromised," **Valve** stated in its notification.
The compromised data includes customers' names, physical addresses, phone numbers, email addresses, and details about the type and price of the products ordered.
Crucially, **Valve** emphasized that no additional information related to **Steam** accounts or other purchases was affected. **CEVA Logistics** does not have access to payment information, passwords, **Steam Guard** codes, or other sensitive account data.
However, **Valve** issued a strong warning to affected **Steam** customers about potential follow-up phishing attempts. Attackers may leverage the stolen information to craft convincing email, SMS, or voice phishing messages, impersonating **Steam**, **Valve**, or delivery companies.
"They may quote your address back to you to prove they're genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to 'verify' your order. Treat all of them as fake. You do not need to change your **Steam** password, and you don't need to do anything to your account settings," the company advised.
**Valve** confirmed it is pressuring **CEVA** for a comprehensive understanding of the breach's scope and is in the process of notifying relevant data protection authorities across the affected countries. **CEVA Logistics** has isolated the compromised systems, taken them offline, and engaged external investigators.
This disclosure from **Valve** follows earlier reports on August 1, where **CEVA Logistics** informed several European retailers about a cyberattack that disrupted operations at eight of its European warehouses.