Valve Warns Steam Users After CEVA Logistics Data Breach — What You Need to Know

Valve Warns Steam Users After CEVA Logistics Data Breach — What You Need to Know

Valve says a shipping partner breach leaked delivery details tied to some European Steam customers. Here’s what was taken, why targeted phishing may follow, and how you can respond safely.

What Happened?

According to CyberInsider, Valve warned Steam customers in Europe about a data breach at shipping partner CEVA Logistics.

CEVA delivers physical Steam products, including the Steam Deck and related hardware.

The cyberattack took place between July 29 and August 1, 2026. Valve learned on August 7 that some customer information may have been accessed.

CEVA may keep delivery information for up to 90 days after an order. This means some recent Steam hardware buyers could be affected.

Valve says CEVA took affected systems offline and brought in outside investigators. Valve is also notifying relevant European data protection authorities.

Data breaches like this can create risks long after the original incident. Your information may also have been leaked in other breaches without you realizing it.

That is why checking for leaks can help you spot potential problems earlier. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Affected and What Data Was Leaked?

The breach may affect some Steam customers in Europe who recently ordered physical Steam hardware.

Valve has not publicly shared how many customers were affected.

The leaked information may include:

  • Names
  • Street addresses
  • Postal codes
  • Cities and countries
  • Phone numbers
  • Steam account email addresses
  • Type of Steam hardware ordered
  • Price of the hardware

CEVA did not have access to Steam passwords, Steam Guard codes, payment information, or details about unrelated purchases.

Even without passwords or payment details, this information can still be valuable to criminals. They may use your order details to make phishing messages look believable.

How Hackers Accessed CEVA Logistics Systems

CEVA has not publicly explained exactly how criminals entered its systems.

That means we do not yet know whether the attack involved stolen passwords, harmful software, a security weakness, or another method.

Valve says it is asking CEVA for more information about the cause and full scope of the incident.

Check if your data is safe from scammers

Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.

Check my safety