GameRiotBeta
All Stories
Steam Hardware Buyers in Europe Hit by Data Breach via CEVA Logistics Cyberattack
TrendingSteamData BreachValveCybersecurity

Steam Hardware Buyers in Europe Hit by Data Breach via CEVA Logistics Cyberattack

Aug 11, 20267 sources0 comments

Valve has begun notifying European customers who purchased Steam hardware that their personal information may have been compromised, following a cyberattack on CEVA Logistics, the company responsible for shipping Steam hardware across Europe. The attack, which reportedly took place in early August 2026, targeted CEVA's systems rather than Valve's own servers. Valve has been clear that its internal infrastructure was not breached, but customer data handled by the logistics partner was likely exposed.

The affected customers are primarily those who ordered Steam hardware, such as the Steam Machine and Steam Controller, within roughly the past three months. Valve has warned those customers to be vigilant and to "expect fake messages," as the stolen personal information could be used to craft convincing phishing emails or other scam communications. The company is urging users to treat any unexpected messages with caution, particularly those requesting account credentials or payment details.

Key Insights

  • 1The breach originated at CEVA Logistics, Valve's European shipping partner, not on Valve's own servers, which remain secure.
  • 2European customers who ordered Steam hardware (including the Steam Machine and Steam Controller) in the past three months are the primary group at risk.
  • 3Valve has proactively notified affected customers and warned them to 'expect fake messages,' signaling a real risk of follow-up phishing or scam attempts.
  • 4The incident highlights the growing security risk posed by third-party supply chain and logistics partners, even when a company's core infrastructure is unaffected.
  • 5Users should scrutinize any unsolicited emails or messages referencing their Steam hardware orders and avoid clicking suspicious links or providing personal information.