Valve Confirms CEVA Logistics Cyberattack Likely Exposed European Steam Hardware Customer Data
By CriticalPixel ·
Valve is in damage control mode this week after a cyberattack on its European shipping partner, CEVA Logistics, likely handed attackers the personal details of an unknown number of Steam hardware customers. The company began emailing affected buyers on August 8, and the wording is blunt: a breach happened between July 29 and August 1, and Valve learned of it on August 7. If you bought a Steam Deck, a Steam Controller, a Steam Frame, or any other Valve-made hardware shipped to a European address in roughly the last 90 days, treat your inbox like a live minefield.
The stolen data set is small but sharp. According to the notification Valve sent out, attackers had access to names, street addresses, phone numbers, email addresses, and the type and price of the order. That is the precise kind of information phishing outfits dream about, because a follow-up message quoting your real address and your real purchase is terrifyingly convincing. Valve explicitly told customers they do not need to change their Steam password and that no Steam Guard codes, payment data, or unrelated account information was exposed, because CEVA never had it. The shipping company only stores delivery info for about 90 days after an order, which is the entire window Valve is now warning about.
What we know about the CEVA Logistics breach
CEVA Logistics is not a small outfit. It is a France-headquartered shipping and logistics company with over 1,000 warehouses worldwide, owned by CMA CGM, the third-largest shipping conglomerate on the planet. CEVA reported $18.3 billion in revenue for 2025 and handled roughly 15 million shipments last year. The company confirmed to TechCrunch that the cyber intrusion hit at least eight of its European contract logistics warehouses, took some applications offline, and triggered shipping delays that have rippled through retail partners across the continent. Dutch online giant Bol, luxury department store De Bijenkorf, Dutch banking giant ING, football club Ajax, and eyewear chain Ace and Tate are all on the list of organizations that have publicly confirmed customer data was taken from CEVA's systems.
The Dutch data protection authority told TechCrunch it has already received breach reports from 10 organizations linked to the same incident, which strongly suggests the total impact is much wider than gaming. CEVA's own website was misbehaving for a chunk of last week, and the company has not publicly answered the obvious follow-up questions, like whether a ransom demand landed or how much data was actually pulled. Spokespeople would not share the scope of what was taken. That silence is the kind of thing that will keep brewing long after the next patch.
Why this hits Steam harder than it looks
On paper, Valve dodged the worst case. No passwords leaked, no payment data leaked, no Steam Guard codes leaked, and the breach is contained to a specific 90-day shipping window. In practice, the company just confirmed that a third party it trusted with physical delivery of its hardware was breached badly enough that regulators are involved in multiple countries. Steam has spent the better part of a decade building a reputation as the most reliable, least intrusive storefront in PC gaming. Having its name attached to a logistics supply chain breach is not the headline Valve wanted, and it is the precise kind of incident that makes the next round of privacy regulation feel urgent.
There is also a real phishing risk for European Steam Deck owners specifically. Attackers now know the names, emails, addresses, and what someone paid for their hardware. A convincing fake email claiming a customs fee, a delivery reattempt, or a warranty verification could easily land, and Valve is explicitly warning customers that any message quoting their real order back to them is still fake. The right move is to ignore every link in any unexpected email about a Steam order, sign into Steam only through the official client or website, and never reauthenticate on a page you reached by clicking an email link. If you have to do anything, do it from the Steam client itself.
Community reaction and the wider pattern
Reaction across Reddit's r/Steam, r/valve, and r/gaming has been muted, mostly because there is not much to do. The most-upvoted response across those threads is the same one BleepingComputer and PC Gamer both reported: this is a third-party problem Valve inherited, and the real fix is regulator pressure on shipping providers, not a Steam patch. The Dutch regulator has confirmed it is investigating, which is the part that actually matters. If CEVA is found to have failed basic cybersecurity obligations, the resulting fines will land on the shipper, not on Valve, and that is the lever customers have.
Wider, this is the third high-profile logistics and supply chain breach to hit gaming-adjacent infrastructure in the last 12 months, and it follows a well-known pattern: attackers go after the weakest link in the chain, not the brand name at the top. The right corporate answer is shorter data retention windows, tighter vendor security audits, and forcing shippers to delete customer data on a much shorter cycle than 90 days. CEVA's 90-day retention policy is industry standard, which is precisely the problem. The standard is too loose for 2026.
What Steam customers should actually do
If Valve emailed you, the practical to-do list is short. Do not click any link in the email itself, even if it looks like a Steam security follow-up. Open the Steam client, navigate to your purchase history through the official app or store.steampowered.com, and verify your hardware orders directly. Do not change your Steam password unless Steam tells you to in a signed-in client notification, because phishers love password reset links. If you want one belt-and-braces move, enable Steam Guard two-factor authentication if it is not already on, and consider a unique password manager entry for any account that ever shipped a Steam Deck to your home.
Valve says it is pressing CEVA for the full scope of the incident, working with data protection authorities across Europe, and continuing to investigate. None of that helps anyone who already got the email, but it does set up the regulatory payoff that should land in the next 6 to 12 months. For everyone else, this is a good reminder that your order data has a half-life, and that the safest Steam account is the one whose email and shipping address are not floating around in a logistics company's database.