mimile
Back to feed
This event is part of a larger story
Франция, Казахстан, Польша: кибератаки раскрыли данные сотен тысяч
Read briefing

Valve warns Europe Steam hardware buyers after CEVA Logistics hack exposes personal data

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Valve warns Europe Steam hardware buyers after CEVA Logistics hack exposes personal data

Valve warns European Steam hardware customers that their personal information was stolen in a cyberattack on shipping partner CEVA Logistics between July 29 and August 1. The company learned of the breach on August 7 and says compromised data includes names, addresses, phone numbers, and hardware order details. Payment information, passwords, and Steam Guard codes were not accessed, the company said.

The Breach

CEVA Logistics, Valve's European hardware distributor, suffered a cyberattack between July 29 and August 1, 2026. Valve disclosed on August 7 that hackers had accessed personal information of customers with pending or recent Steam hardware orders. CEVA isolated affected systems upon discovery and notified data protection authorities, bringing in external investigators.

Exposed Data

The stolen data includes customer names, shipping addresses, phone numbers, email addresses, and product order details such as type and price. CEVA retains this delivery-related information for 90 days after purchase. Valve confirmed that payment card details, Steam account passwords, and Steam Guard authentication codes were not compromised, as the logistics partner never held that data.

Valve's Advisory

Valve warns affected customers to expect fake messages via email, SMS, or phone that reference their hardware orders and appear to come from Steam, Valve, or delivery companies. Scammers may request additional customs or delivery fees, or link to fraudulent login portals. The company emphasizes that Steam Support will never ask for passwords or Steam Guard codes, and users should only log in at official domains: help.steampowered.com, store.steampowered.com, or steamcommunity.com.

What's Next

Valve has not disclosed the number of affected customers, nor whether the attackers have been identified. It remains unclear how the stolen data might be used beyond phishing attempts, but customers are advised to monitor unusual communications.