Valve Reports Data Breach After Attack on Logistics Partner
Video game giant Valve is informing its European Steam hardware customers that their personal data was exposed following a cyberattack on its shipping partner, CEVA Logistics. Attackers reportedly accessed information including names, addresses, and order details.
What Happened
Valve, the heavyweight of the gaming world, has issued a data breach notification to its Steam hardware customers in Europe. In emails sent to users, the company clarified that the breach did not originate from its own systems but from a cyberattack targeting its logistics partner, CEVA Logistics, which handles its shipping operations. This incident highlights how a vulnerability in the supply chain can put the data of thousands of customers at risk, even if the primary company remains unscathed.
According to the notification emails sent by Valve, the attack took place between July 29 and August 1, 2026. During this period, cyberattackers infiltrated the servers of CEVA Logistics, gaining access to customer information necessary for shipping Steam hardware orders. Valve stated that it became aware of the situation on August 7 and immediately began the process of informing affected customers. The company emphasized that it sent this notification to all customers who could potentially be impacted, due to CEVA's policy of retaining order information for up to 90 days.
The targeted company, CEVA Logistics, is a major global logistics firm. As a subsidiary of the CMA CGM Group, the world's third-largest shipping company, CEVA operates over 1,000 warehouses and, in 2025, handled 15 million shipments, generating revenues of $18.3 billion. The targeting of such a large-scale operation underscores the seriousness of the attack and the wide scope of its potential impact.
What Data Was Exposed
According to Valve's statement, the data compromised by the attackers is directly related to order delivery. This data includes sensitive information that could pose risks to customers' physical security and digital identity. The types of data affected by the breach are:
- Full Name: Essential information used for personalizing phishing attacks.
- Delivery Address: Physical location information, such as customers' home or work addresses.
- Phone Number: Can be used for phishing attacks conducted via SMS or voice calls (smishing/vishing).
- Email Address: The primary target for spear-phishing attacks.
- Type and Price of Ordered Product: Information that attackers can use to make fraudulent delivery or customs fee requests more convincing.
Valve offered a crucial piece of reassurance on this point. The company stated that CEVA Logistics does not have access to customer payment information, Steam account passwords, Steam Guard codes, or other sensitive account data. While this means that attackers cannot directly take over Steam accounts or commit financial fraud, it is important to remember that the stolen personal information is extremely valuable for phishing campaigns.
How the Attack Occurred
Based on available information, the cyberattack targeted CEVA Logistics, which manages hardware shipments for Valve in Europe, rather than Valve's own infrastructure. Attackers gained unauthorized access to CEVA's servers between July 29 and August 1, 2026. Technical details, such as the specific vulnerability exploited, the cybercrime group responsible, or whether it involved ransomware, have not yet been made public.
CEVA Logistics announced that upon discovering the attack, it isolated the affected systems, took them offline, and engaged external, independent cybersecurity experts to investigate the incident. It is known that on August 1, CEVA also informed its other retail partners in Europe about a cyberattack affecting its operations. This suggests that the impact of the attack may not be limited to Valve's customers. As the investigation continues, more details about the full scope and method of the attack are expected to emerge.
Who Is Affected
Those directly affected by the data breach are Steam customers residing in Europe who have ordered physical hardware from Valve, such as the Steam Deck or Valve Index. Valve stated that it sent notifications assuming all customers who had placed or received an order within the last three months were potentially at risk, due to CEVA's 90-day data retention policy. If you have recently ordered Steam hardware to an address in Europe, you may have been affected by this breach.
What You Can Do
Valve has issued clear warnings and recommendations for affected customers. Phishing attacks may be launched against you using your leaked information. Therefore, it is critically important to pay attention to the following steps:
- Be Skeptical of All Communications: Be extremely cautious with anyone contacting you via email, SMS, or phone, claiming to be from Valve, Steam, or a shipping company (CEVA, DHL, UPS, etc.).
- Don't Fall for Verification Ploys: Attackers may recite your address or the product you ordered to gain your trust. This does not mean they are legitimate; they already possess this information.
- Watch Out for Fake Requests: You may receive messages with requests to "confirm delivery," "pay a small customs fee," "pay a redelivery fee," or log in somewhere to "verify" your order. Treat all of them as fake.
- No Need to Change Your Password: Valve specifically stated that this breach did not affect your Steam account information, so there is no need to change your Steam password or account settings.
- Use Official Channels: If you have any doubts about your order, do not click on links in emails you receive. Instead, go directly to the official Steam website by typing the address into your browser, log in, and check your order status there.
What the Company Is Saying
Valve has indicated that it is taking the incident very seriously and is conducting a transparent communication process. In the email sent to customers, the company stated, "We're pressing CEVA for the full scope of what was taken and how, and we are in the process of notifying the data protection authorities in the countries affected, including yours." The company also confirmed that CEVA has isolated the affected systems and is working with external investigators.
It was also reported that the news source BleepingComputer reached out to Valve for additional comment but had not received a response at the time of publication. CEVA Logistics has stated that the investigation is ongoing and they are working to restore normal operations.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.