Valve started emailing European Steam hardware buyers this morning to tell them their delivery details were stolen. The break-in was not at Valve. It happened at CEVA Logistics, the contractor that warehouses and ships Steam Machines, Steam Controllers and Steam Decks across Europe. Attackers had access to CEVA systems between July 29 and August 1, 2026, Valve was informed on August 7, and the customer notice went out on August 10.
No Steam account was touched. What leaked is the boring layer nobody thinks about when they buy a console: the file that says who you are, where you live, and what expensive thing is arriving at your door.
RelatedAssuranceAmerica Breach Hit 6.9M Driver's Licenses
- Exposed data covers names, street addresses, postal codes, cities, countries, phone numbers, email addresses, and the type and price of the Steam hardware ordered.
- Steam passwords, Steam Guard codes, payment cards and account data were never held by CEVA and are not part of this incident.
- Only European hardware orders placed in roughly the last 90 days are affected, because 90 days is CEVA's retention window.
- Valve is warning about follow-up emails, texts and phone calls that quote your real address to sound legitimate.
What actually happened at CEVA?
CEVA Logistics is a CMA CGM subsidiary running roughly a thousand warehouses and moving about 15 million shipments a year. Eight of its European warehouses were disrupted over the weekend that the intrusion ended, and CEVA told its contract-logistics customers on August 1 that a cyber intrusion was affecting part of that operation. Valve was a downstream victim of that notification chain, six days later.
The gap matters. The attackers left on August 1. Valve heard on August 7. Customers heard on August 10. For nine days, somebody had a list of European gamers with fresh, high-value hardware orders, and nobody on that list knew.
- Jul 29, 2026Attacker access to CEVA systems begins start of the intrusion window Valve later disclosed
- Aug 1, 2026Access ends, CEVA notifies logistics customers eight European warehouses disrupted
- Aug 7, 2026CEVA tells Valve Steam customer data was likely taken six days after the window closed
- Aug 10, 2026Valve emails affected European hardware buyers phishing warning attached
- OngoingDutch Data Protection Authority investigation opened over the same incident at other retailers
Why does a shipping vendor hold this much?
Because it has to. A third-party logistics provider cannot put a box on your doorstep without your name, address and a phone number for the courier, and it cannot handle customs or returns without knowing what is in the box and what it was worth. So the fulfilment layer ends up holding a tidy dossier: identity, location, and a priced inventory of what you just bought.
That combination is worth more to a fraudster than a password dump. A stolen credential needs a login to be useful and gets killed by two-factor. A verified shipping record needs nothing. It tells an attacker that a specific person at a specific address is expecting a specific expensive parcel in a specific window, which is the ideal setup for a delivery scam and, for the unlucky few, for a porch theft.
Valve's own hardware makes this sharper than usual. The Steam Machine sells for $1,049, so a leaked line item does not just say "electronics", it says four figures.
Who else got caught in the same breach?
Valve is not the story on its own. The same CEVA incident has now produced separate customer notifications from at least two large Dutch retailers, which is what turns this from a gaming story into a supply-chain one.
| Valve / Steam | bol. | De Bijenkorf | |
|---|---|---|---|
| Notified customers | Aug 10, 2026 | Early August 2026 | Early August 2026 |
| Data described | Name, address, phone, email, item and price | Name, address, phone, tracking and order details | Potential exposure via external logistics partner |
| Scope | EU hardware orders, last ~90 days | Dutch e-commerce orders | Department store orders |
| Regulator engaged | Not stated | Reported to Dutch DPA | Not stated |
One vendor, three consumer brands, three separate apology emails. None of the three did anything wrong at their own perimeter. This is the shape modern retail breaches take now: the customer-facing company is secure, and the compromise arrives through the company that touches the parcel.
What will the scam messages look like?
Valve was unusually direct about this, and its wording is the useful part of the notice. Attackers can impersonate Valve, Steam, or a delivery company, and ask for a customs fee, a redelivery payment or an account login. As Valve put it, they may quote your address back to you to prove they are genuine, and the advice is to treat all of them as fake.
Relatedkhunt Turns Oracle SQL Injection Into Windows SYSTEM
The economics are simple. The fee is small on purpose. Nobody disputes 2.99 euros, and the point was never the 2.99, it was the card number typed into the payment page. The second variant is worse: a "confirm your Steam account to release the shipment" page that harvests credentials and a Steam Guard code in real time.
What should Steam hardware buyers do now?
Nothing about your account is broken, so there is no password to rotate and no card to cancel. The work is behavioural, and it applies for months rather than days, because shipping records do not expire the way credentials do.
Treat any unsolicited message about a Steam delivery as hostile, including ones that get your address right. Never pay a customs or redelivery fee from a link. Check order status from the Steam client or the Steam Store directly rather than from anything sent to you. If you receive a phone call about the shipment, hang up and call the courier back on a number you looked up yourself. And keep Steam Guard on, because it is the one control that still stands between a convincing phishing page and your library.
- A wave of EU-language delivery smishing. The data is regional and recent, so expect Dutch, German and French templates rather than generic English ones.
- More brands joining the list. CEVA ships for many retailers. Valve, bol. and De Bijenkorf are unlikely to be the last three notifications from this single intrusion.
- A GDPR file. The Dutch DPA is already involved. A third-party processor breach touching this many controllers is the kind that produces a public finding.
- Retention pressure. The 90-day window is the only reason this is not far worse. Expect that number to become a negotiating point in logistics contracts.
Our take
The instinct on a story like this is to grade Valve, and Valve comes out fine: it disclosed within three days of being told, it named the vendor instead of hiding behind "a third party", and it told people exactly what the scam would sound like. That last part is rarer than it should be.
The uncomfortable read is that none of it was Valve's decision to make. Your address, your phone number and the price of your console sat in a vendor's database on a 90-day timer, and the only defence you had was that timer. Every company that outsources fulfilment has this exposure, and almost none of them describe it to customers before something goes wrong. Until that changes, the practical security posture for buying hardware online is to assume the shipping layer is public, and to distrust anything that arrives claiming to know where you live.
- VendorCEVA Logistics the CMA CGM contract-logistics arm at the centre of the incident
- StoreSteam Hardware on the Steam Store official order and support path, the only one to trust for status
- RegulatorAutoriteit Persoonsgegevens Dutch DPA, investigating the same CEVA incident
- ReportBleepingComputer on the Valve notification first detailed write-up of the customer email
- ContextOur coverage of the $1,049 Steam Machine what is actually in these parcels
Original analysis by GenZTech. Reporting on Valve's customer notification via BleepingComputer.
