
A cyberattack on one of Valve’s European logistics partners has exposed personal information belonging to customers who recently purchased or ordered Steam hardware, including the new Steam Machine and Steam Controller.
Valve has begun warning affected customers after learning that CEVA Logistics, the company responsible for shipping Steam hardware to customers across Europe, suffered a cyberattack between July 29 and August 1, 2026.
The incident did not directly compromise Valve’s Steam platform, but attackers were able to access information held by the logistics company for hardware deliveries.
The breach is particularly concerning because the stolen information can potentially be used to create highly convincing phishing and delivery scams aimed specifically at Steam hardware buyers.
What Happened to Steam Machine and Steam Controller Customers?
According to Valve’s notification to customers, CEVA Logistics was hit by a cyberattack between July 29 and August 1.
Valve says it learned about the incident on August 7 and subsequently began notifying customers whose information may have been affected.
CEVA handles logistics for Steam hardware shipments in Europe, meaning it receives certain information from Valve that is necessary to deliver products to customers.
The company retains this information for up to 90 days, which is why the potential impact extends beyond people who received their hardware only recently.
The timing is particularly notable for Valve’s hardware business.
The Steam Controller launched earlier this year, while the Steam Machine has also generated significant interest from PC gamers preparing for Valve’s return to the living-room gaming market.
The attack therefore potentially affects people who purchased Valve hardware during this period, rather than all the Steam Machine or Steam Controller themselves.
What Customer Information Was Exposed?
The information potentially accessed by the attackers is primarily delivery and purchase information.
Valve says the compromised information may include the customer’s name, street address, city, postal code, country, phone number, and email address.
The data can also include information about the hardware order, including the type of product purchased and its price.
This is important because the information can be combined to make fraudulent messages appear legitimate.
For example, an attacker who knows that someone purchased a Steam Controller and has their real delivery address could send a message claiming that the package is being held by a courier.
The scam could then ask the victim to pay a small redelivery or customs fee, confirm their address, or sign into a fake Steam page.
Valve is specifically warning customers to expect this type of targeted phishing.
Steam Accounts and Payment Details Were Not Compromised
There is an important distinction between this incident and a direct Steam account breach.
Valve says CEVA does not have access to customers’ Steam passwords, Steam Guard codes, or payment information.
The breach therefore does not mean that hackers obtained Steam Wallet balances, credit-card details or Steam account credentials through this incident.
Valve’s warning also indicates that customers do not need to change their Steam passwords solely because of this particular breach.
That said, affected users should still remain extremely cautious about messages relating to their Steam hardware orders.
Why This Could Lead to More Convincing Scams
The biggest danger may come after the data breach rather than from the stolen information itself.
Generic phishing emails are often relatively easy to identify because scammers do not know much about their targets. This breach potentially gives attackers considerably more useful information.
A fake message could mention the exact Steam product someone ordered, use their real name and address, and claim that their shipment requires an additional payment.
To an unsuspecting customer waiting for a Steam Machine or Controller, such a message could look surprisingly convincing.
Valve specifically warned that scammers may use email, SMS, or phone calls and may impersonate Valve, Steam, or a delivery company.
Attackers could even quote a customer’s address back to them in an attempt to make the communication appear authentic.
This makes the incident a classic example of why supply-chain security matters. A company does not necessarily have to breach Valve’s own infrastructure to obtain information about Valve’s customers.
The Attack Also Affected Other Companies
The CEVA incident appears to be much broader than Valve’s Steam hardware operation.
CEVA Logistics is a major global logistics company, and reports indicate that the cyberattack affected multiple European warehouses and other businesses using the company’s logistics infrastructure.
TechCrunch reported that at least eight warehouses in Europe were affected by the incident. That means Steam customers are only one group potentially caught up in the wider breach.
For Valve, however, the incident is particularly awkward because the affected hardware includes some of its most anticipated products.
Customers who have been waiting for their Steam Machines or recently purchased Steam Controllers now have to be particularly careful about communications surrounding their orders.
What Steam Hardware Owners Should Do
Valve says users affected by the breach should treat unexpected messages concerning their Steam hardware orders as suspicious.
If someone receives an email, SMS, or phone call claiming that their Steam Machine or Steam Controller needs an additional payment, delivery confirmation, or account verification, they should not use the provided link or give the caller any account information.
Steam Support also warns users that legitimate Steam support will not ask for passwords or Steam Guard codes.
Valve recommends checking account activity and being cautious with unsolicited messages claiming to come from Steam Support.
The safest approach is to access Steam directly rather than clicking a link received in an email or text message.
Users should also avoid providing Steam credentials, Steam Guard codes, or payment information to anyone claiming to be a courier or Valve representative.
Valve Is Investigating the Situation
The full scope of the CEVA breach is still being investigated.
Valve has said it is pressing CEVA for more information about what was accessed and how the attackers obtained it.
The company is also notifying relevant data protection authorities in the affected countries.
The breach instead demonstrates how third-party suppliers can become an indirect route to customer information.
The incident is another reminder that buying hardware from a major gaming company does not necessarily mean all of the information surrounding that purchase is stored within the company’s own systems.
Valve says it will continue working with CEVA to determine the full scope of the incident and will provide further information as the investigation develops.
