Valve alerts Steam buyers after logistics data breach
Valve has warned Steam hardware customers across Europe that their personal and order information was likely stolen during a cyberattack on CEVA Logistics, the company responsible for distributing its physical products in the region. The attack gave intruders access to CEVA systems between July 29 and August 1, 2026. Valve learned on August 7 that information belonging to its customers was among…
Valve notified Steam purchasers in Europe after learning a cyberattack on CEVA Logistics exposed their personal and order data. This breach occurred between July 29 and August 1, 2026, and affected customers who placed hardware orders during that period. The stolen information included names, delivery addresses, phone numbers, email addresses, and details about the type and cost of the Steam hardware purchased.
Payment information, Steam passwords, and Steam Guard codes remained untouched. Valve warned customers about potential phishing attempts using the stolen data, urging them to be cautious of fraudulent communications demanding small fees or asking for Steam credentials. The logistics provider retained delivery data for 90 days to manage returns and fulfillment issues.
CEVA reported that the attack affected eight European warehouses and disrupted some operations, while other companies using CEVA facilities also experienced delivery delays. The logistics firm stated it had isolated the affected systems and engaged external investigators. Valve is currently working with CEVA to ascertain the extent of the data breach and how the intruders obtained access to the information.
The incident underscores the risks associated with breaches involving routine shipping data, as combining personal details with purchase information can facilitate sophisticated social engineering attacks.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.