All stories
Hardware

CEVA Logistics Breach Exposes European Steam Hardware Customer Data

A cyberattack on Valve's European shipping partner, CEVA Logistics, has exposed personal delivery information for European Steam hardware customers, including names, addresses, and order details.

By TECH NEWS Editorial·Source:Engadget·4 min read·1h ago

This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
CEVA Logistics Breach Exposes European Steam Hardware Customer Data

A recent cyberattack on CEVA Logistics, Valve's European shipping partner, has "likely compromised" the personal data of European Steam hardware customers who placed orders between late July and early August 2026. This incident, confirmed by Valve to affected users on August 7, 2026, reveals that critical delivery-related information, including names, full street addresses, postal codes, cities, countries, phone numbers, email addresses, and details of the hardware ordered (type and price), was exposed. Crucially, Valve has reassured customers that payment information, passwords, and Steam Guard codes were not accessed, as CEVA Logistics does not store these highly sensitive data points. The breach, which occurred between July 29 and August 1, 2026, impacts customers who purchased devices like the Steam Deck, Steam Machine, or Steam Controller, with CEVA retaining such shipping data for up to 90 days.

This compromise of a third-party logistics provider underscores a growing vulnerability across the tech industry: supply chain attacks. While Valve's core systems and user account security, bolstered by features like Steam Guard and multi-factor authentication, appear to have held firm, the incident highlights that data is only as secure as the weakest link in its processing chain. For users, the primary concern now shifts from direct account compromise to the heightened risk of sophisticated phishing and social engineering attacks. Valve has explicitly warned affected customers to "expect fake messages — email, SMS or phone — that mention your hardware order and appear to come from Steam, Valve or a delivery company," cautioning that these scams may use the leaked address and order details to appear legitimate and solicit further personal information or payment for fake customs or redelivery fees. This kind of targeted attack, known as spear-phishing, is significantly more dangerous than generic phishing attempts due to its personalized nature.

The incident comes at a time when the gaming industry is experiencing unprecedented growth, with Steam itself boasting an estimated 198-200 million monthly active users globally in late 2025, potentially making it over 50% larger than PlayStation Network. This massive user base, combined with the increasing popularity of hardware like the Steam Deck (which had shipped approximately 3.7 million units by the end of 2024 and around 4 million by February 2025), makes Valve and its partners attractive targets for cybercriminals. The cybersecurity in gaming market was valued at $14.8 billion in 2025 and is projected to reach $42.6 billion by 2034, driven by a surge in online gaming, rising DDoS and account-takeover attacks, and increasing regulatory scrutiny. Cyberattacks targeting gaming platforms have seen a 167% increase in DDoS incidents between 2022 and 2025 alone.

This is not Valve's first encounter with data security issues. A significant breach in November 2011 exposed usernames, hashed and salted passwords, game purchases, email addresses, billing addresses, and encrypted credit card information for approximately 35 million users, with a subsequent disclosure in early 2012 revealing that a backup file with transaction data from 2004 to 2008 was also likely stolen. That incident led to Valve implementing enhanced security measures, including requiring two-factor authentication for game developers and rolling out Steam Guard. While the current breach affects a different type of data and a third-party vendor, it highlights the persistent challenge of securing a complex digital and physical supply chain.

For the wider industry, this event serves as a critical reminder that even with robust internal security, reliance on third-party vendors introduces external risk vectors. Regulatory bodies, particularly under GDPR in Europe, are likely to scrutinize such breaches closely, potentially leading to fines depending on CEVA Logistics' and Valve's demonstrated compliance and response. Regulatory frameworks governing data privacy in online gaming have multiplied significantly since 2022, driving mandatory security spending.

Looking ahead, Valve is reportedly "pressing CEVA for the full scope of what was taken and how" and is "in the process of notifying the data protection authorities in the countries affected". Users should remain highly vigilant, treating any unsolicited communications related to their hardware orders with extreme suspicion. The long-term implications for Valve's reputation, while likely not catastrophic given the contained nature of the breach, will depend on the transparency and effectiveness of their ongoing response and future preventative measures within their supply chain. The incident will undoubtedly fuel further calls for end-to-end encryption and zero-trust architectures across all touchpoints, including logistics partners, as cybersecurity continues to be a defining battleground in the digital economy.

Sources