Valve warns Steam hardware buyers after shipping partner CEVA was hacked

By: Anton Kratiuk | today, 18:08
Valve notified affected European Steam hardware customers about the CEVA data breach on August 7, 2026. Valve notified affected European Steam hardware customers about the CEVA data breach on August 7, 2026.. Source: Source: Valve

If you bought a Steam Deck, Steam Controller, or Steam Machine in Europe, your shipping data may now be in the wrong hands. Valve's logistics partner CEVA was hit by a cyberattack between July 29 and August 1, 2026, and Valve confirmed the breach on August 7. The exposed data is the kind that fuels convincing scams — even if your Steam account itself is untouched.

What was exposed

CEVA handled European hardware shipments for Valve. To process orders, Valve passed along customer names, home addresses, phone numbers, email addresses, and hardware type with purchase price. All of that is now potentially compromised, per BleepingComputer.

What was not exposed: Steam passwords, Steam Guard codes, or payment information. Valve was careful to separate those systems from what CEVA could access.

CEVA retains order data for up to 90 days after an order is placed, meaning anyone who bought Steam hardware from around late April onwards is in scope. The breach hit eight European CEVA warehouses, and its ripple effects have reached other companies too — Dutch retailer Bol, department store De Bijenkorf, football club Ajax, bank ING, and eyewear brand Ace & Tate were also affected, reports TechCrunch.

Valve notified affected European Steam hardware customers about the CEVA data breach on August 7, 2026.
Valve notified affected European Steam hardware customers about the CEVA data breach on August 7, 2026.

The scam risk

A home address combined with an order history is enough to craft a highly believable phishing message — think fake delivery fee requests, parcel verification texts, or emails impersonating Steam Support. Valve explicitly warns that it will never contact customers by email, Steam chat, X, Discord, or any third-party platform to resolve support issues. Everything goes through the official Steam website only.

The company also repeated its standing advice: never share your Steam password or Steam Guard code with anyone, under any circumstances.

Supply-chain exposure

CEVA is a fully owned subsidiary of CMA CGM, the world's third-largest shipping company, with $18.3 billion in revenue in 2025. Valve says it is still waiting for a full incident report from CEVA. No threat actor has been publicly named.

The breach fits a wider pattern. DHL, Maersk, and Expeditors International have all faced similar attacks in recent years — logistics firms hold real-world customer data at scale, making them attractive targets even when the companies they serve keep their own systems locked down.

If you received a notification from Valve, treat any unexpected delivery or fee message as suspicious and report it directly through Steam's official support page.