Steam user data 'may have been compromised' by a cyberattack targeting Valve's European shipping partner
An attack targeting CEVA Logistics "likely" exposed the personal information of European customers who ordered Steam hardware, Valve says.
Steam, the popular online gaming platform, issued a notice to its European customers on July 29, alerting them of a potential data breach that may have compromised personal information. The cyberattack targeted CEVA Logistics, a European shipping partner of Valve responsible for fulfilling hardware orders for customers in Europe.
The attack occurred between July 29 and August 1, 2026. Valve confirmed the breach on August 7, and the compromised data includes names, addresses, phone numbers, email addresses, and order details. Valve advises affected users to remain vigilant against fraudulent communications and not to change their passwords, as their Steam accounts remain secure.
CEVA Logistics, the affected shipping company, is currently investigating the incident and working with data protection authorities in European countries. The cyberattack has caused shipping delays across Europe for Valve's retail partners.
Written by urgent.news from PC Gamer's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.