Cybersecurity

Steam Hardware Buyers in Europe Targeted by Cyber Attack on Logistics Firm

A cyberattack on logistics firm CEVA Logistics has compromised personal data of European Steam hardware customers, including names and addresses. Valve is warning affected users to beware of phishing attempts.

Joshua Ramos
Joshua Ramos covers cybersecurity for Techawave.
2 min read0 views
Steam Hardware Buyers in Europe Targeted by Cyber Attack on Logistics Firm
Share

Steam hardware customers in Europe are being alerted to a data breach that occurred between July 29 and August 1, 2026. The incident impacted CEVA Logistics, the third-party company responsible for shipping Steam hardware to buyers across the continent. While CEVA Logistics is still investigating the full scope of the attack, Valve confirmed on August 7 that customer information was likely compromised.

The compromised data includes delivery-specific details provided by Steam to CEVA. These details, which the attackers likely accessed, may include customer names, street addresses, city, postal codes, country, phone numbers, and the email address associated with their Steam account. The type and price of the ordered product may also have been exposed. Valve has emphasized that information directly related to Steam accounts, such as payment details, passwords, or Steam Guard codes, was not affected as CEVA does not have access to such sensitive data.

Warning Issued Against Phishing Scams

Valve is urging affected customers to be vigilant against potential phishing attacks. Scammers may use the leaked information, such as customer names and addresses, to craft convincing fake emails, SMS messages, or phone calls appearing to be from Steam, Valve, or delivery services. These fraudulent messages might request confirmation of a delivery, payment of a small customs fee, or ask users to log in to verify order details. Customers are advised to treat all such unsolicited communications as fake and to never share passwords or Steam Guard codes.

The company stressed that no action is required for customers' Steam accounts, such as changing passwords or adjusting account settings. They reiterated key security advice: Steam Support only operates through the official help portal at https://help.steampowered.com/ and never via email, Steam Chat, or Discord. Legitimate Steam login pages are exclusively found on store.steampowered.com, www.steampowered.com, steamcommunity.com, or help.steampowered.com. Users should always manually type these addresses rather than clicking on links provided by others.

In response to the breach, Valve is pressing CEVA Logistics for comprehensive details regarding the attack and the extent of the data compromised. The company is also in the process of informing data protection authorities in all affected European countries. CEVA Logistics has reportedly isolated the compromised systems, taken them offline, and engaged external cybersecurity investigators to assess the incident. This incident underscores the ongoing risks associated with supply chain vulnerabilities in the cybersecurity landscape, where breaches at third-party vendors can have significant repercussions for end-users.

The attack on CEVA Logistics highlights the importance of robust data security practices, especially for companies handling sensitive customer information during product delivery. While Valve has stated that core account security remains intact, the exposure of personal contact and delivery details necessitates increased user awareness and caution regarding unsolicited communications related to their recent hardware purchases. This event serves as a reminder for consumers and businesses alike about the pervasive nature of cyber threats and the need for continuous vigilance in protecting personal data in an increasingly interconnected digital world.

Share