Protect.Computer
NEWS

Valve Notifies Steam Hardware Customers of Data Breach via Shipper

· 1 min read · Data hijack Identity theft
Valve Notifies Steam Hardware Customers of Data Breach via Shipper

Valve is notifying Steam hardware customers in Europe that hackers stole their personal information after breaking into CEVA Logistics, the company it uses to ship physical hardware orders across the continent. The breach occurred between July 29 and August 1, 2026. Valve says it learned about it on August 7 and is now reaching out to everyone whose data was likely compromised.

CEVA Logistics is a major global shipping and supply-chain company — a fully owned subsidiary of CMA CGM, the world’s third-largest shipping group — handling around 15 million shipments per year from 1,000 warehouses worldwide. Because Valve shares delivery-related information with CEVA so it can fulfill hardware orders (Steam Deck, controllers, and accessories), that data was in scope for the attack. Stolen records include names, postal addresses, phone numbers, email addresses, and the type and price of ordered products. Valve says no Steam account data, passwords, Steam Guard codes, or payment card numbers were involved, because CEVA never has access to those.

How to check if you’re affected

Valve is emailing everyone it believes was affected. Affected products are any Steam hardware items ordered for delivery to a European address during the 90-day window before August 1, 2026. If you placed a Steam hardware order in Europe during that period, treat the notification as genuine — but also be cautious about unsolicited messages claiming to be about your delivery. Valve, Steam, and CEVA will not ask you to pay customs or redelivery fees, click a sign-in link, or provide account credentials to confirm your order. Any message doing so is a scam.

Sources

Related reading