Valve warns European Steam hardware users after data breach

Videogame distributor Valve has warned Steam hardware customers in Europe that their personal and purchase information may have been compromised following a cyberattack on shipping partner CEVA Logistics between July 29 and August 1, with the company warning on August 10 that stolen details could be used for phishing scams.

Valve said it learned of the breach on August 7 and began notifying customers whose delivery information was held by CEVA, which handles physical Steam hardware shipments in Europe. The exposed information may include names, addresses, countries, phone numbers, email addresses, and the type and price of products ordered.

CEVA retains delivery information for up to 90 days after an order, allowing Valve to identify customers who may have been affected. Valve said CEVA does not have access to Steam payment information, passwords, Steam Guard codes or information relating to other purchases.

Valve warned customers to “expect fake messages - email, SMS or phone” that refer to their hardware orders and appear to come from Steam, Valve or a delivery company. The messages could quote genuine addresses or order details to appear legitimate, then ask recipients to pay customs or redelivery fees or enter their credentials on a fake website.

The company said customers should “treat all of them as fake” and do not need to change their Steam passwords or account settings as a result of the breach. Valve added that Steam Support only handles account issues through its official support site and will never request passwords or Steam Guard codes by email, Steam Chat or Discord.

CEVA told Valve that it had isolated the affected systems, taken them offline and brought in outside investigators, while Valve said it was pressing the logistics company for information about the full scope and cause of the incident. Valve is notifying data protection authorities in the affected European countries as the investigation continues.

The breach follows a cyberattack disclosed by CEVA to several European retailers on August 1. The logistics company, a subsidiary of CMA CGM, operates about 1,000 warehouses and handled 15 million shipments in 2025, with revenue of $18.3 billion.

Valve’s warning applies to customers whose Steam hardware orders were handled by CEVA in Europe, including purchases of devices such as Steam Decks and other physical Steam products. The company said customers should type official Steam addresses directly into their browsers rather than follow links contained in messages relating to their orders.



Share Story:

Recent Stories


The future-ready CFO: Driving strategic growth and innovation
This National Technology News webinar sponsored by Sage will explore how CFOs can leverage their unique blend of financial acumen, technological savvy, and strategic mindset to foster cross-functional collaboration and shape overall company direction. Attendees will gain insights into breaking down operational silos, aligning goals across departments like IT, operations, HR, and marketing, and utilising technology to enable real-time data sharing and visibility.

The corporate roadmap to payment excellence: Keeping pace with emerging trends to maximise growth opportunities
In today's rapidly evolving finance and accounting landscape, one of the biggest challenges organisations face is attracting and retaining top talent. As automation and AI revolutionise the profession, finance teams require new skillsets centred on analysis, collaboration, and strategic thinking to drive sustainable competitive advantage.