← Home

CEVA Logistics breach exposes European Steam hardware customers' data

Valve began notifying European Steam hardware customers on Monday after discovering that its shipping partner, CEVA Logistics, suffered a cyberattack. Between July 29 and August 1, 2026, criminals accessed systems belonging to the carrier responsible for shipping physical devices — such as the Steam Deck — to buyers across Europe. The company learned of the issue on August 7 and has since been working to determine exactly what was taken.

The most sensitive leaked data is precisely what CEVA needs to make a delivery: full name, street address, postal code, city, country, phone number, and the email linked to the Steam account. The type and price of the purchased hardware also leaked. On the other hand, Valve was quick to reassure those affected: the carrier had no access to payment details, passwords, or Steam Guard codes, and the Steam account itself was not compromised.

One detail that raises the stakes is the exposure window. CEVA keeps shipping information for up to 90 days after an order, meaning anyone who bought hardware in the last three months could be on the notification list. This is not a small leak: Valve is contacting every customer whose data fell into that window.

The real risk now is the scam. Valve itself warned that the criminals have enough material to run high-quality social engineering. They can quote a victim's address to 'prove' they are legitimate, ask for payment of a supposed customs or redelivery fee, or invite the person to 'verify' the order on a fake site. Email, SMS, and phone calls can impersonate Steam, Valve, or a delivery company.

This incident highlights a structural problem in e-commerce: the security of a transaction depends on every link in the chain. Valve may have state-of-the-art encryption and robust authentication on its platform, but physical shipping data passes through a third party whose perimeter is more vulnerable. It is the same logic as attacks on cloud providers or HR systems: the attacker looks for the weakest link, not the hardest one.

For those notified, the advice is straightforward: do not click links in emails or messages referencing the order, do not pay fees through unofficial channels, and be suspicious of anyone who cites your address to build trust. Valve says no password change is necessary, but an extra layer of skepticism about 'delivery' messages does not hurt.

The episode also raises a broader question about logistics outsourcing at scale. When a giant like Valve entrusts customer data to a transport partner, who is responsible for privacy when that partner fails? Notification is only the first step — the regulatory fallout in Europe, under GDPR, could carry consequences that go well beyond alert emails.

From an operational standpoint, the case also reveals a common weakness in the supply chain: shipping data tends to be treated as less sensitive than payment data, when in practice it is what enables both physical and digital fraud. An attacker holding a name, address, and phone number can intercept deliveries, open accounts in the victim's name, or run social engineering against family members. For this reason, security experts recommend treating shipping details with the same care as access credentials, actively monitoring any unsolicited communication that mentions recent purchases.

Sources: The Verge, Help Net Security, Cybersecurity News

✓ Independent sources cross-checked and verified before publishing