// 1 CRITICAL · 1 ZERO-DAY · 6 CVE · 5 EXPLOIT IN THE LAST 24H
Valve notified European Steam hardware customers on August 7, 2026 that their shipping data was compromised in a cyberattack on logistics partner CEVA Logistics between July 29 and August 1, 2026. Exposed data includes names, full addresses, phone numbers, emails, and product details — but no payment info, passwords, or Steam Guard codes. Valve warns of highly targeted phishing citing victims' actual home addresses.

On August 7, 2026, Valve emailed European customers who purchased Steam hardware — Steam Machine, Steam Controller, and, according to sources, Steam Deck — informing them that their personal shipping data had been compromised. The attack hit CEVA Logistics, the third-party logistics partner handling physical shipments in Europe, between July 29 and August 1, 2026. The notification matters not for the technical severity of the incident itself, but for the risk model it exemplifies: an attack on a fulfillment provider with measured data-retention policies, and a potential phishing campaign personalized down to the victim's home address.

Key Takeaways
  • CEVA Logistics, Valve's European logistics partner, was compromised in a cyberattack between July 29 and August 1, 2026
  • Exposed data includes name, full address, phone number, email, and ordered product type/price; no payment data, passwords, or Steam Guard codes were involved
  • Valve learned of the incident on August 7, 2026 and immediately began notifying customers and data-protection authorities in affected countries
  • CEVA retains shipping data for a maximum of 90 days after an order, limiting the blast radius to hardware buyers from roughly the last three months in Europe

How Data Flowed Between Valve and CEVA

According to Valve's email reported by BleepingComputer and reproduced in full by Digital Foundry, CEVA Logistics receives from Steam the specific information needed for physical fulfillment: shipping address, phone number, email associated with the account, and the type and price of the ordered product. Valve emphasized that CEVA does not hold payment data, passwords, Steam Guard codes, or other Steam account information.

CEVA's retention policy defines the temporal scope of the compromise: data is kept for a maximum of 90 days after the order. This means only customers with hardware purchases within roughly the last three months are potentially exposed, confining the incident to a rolling window rather than Valve's entire European customer history.

The Concrete Risk: Phishing Citing Your Real Address

The operationally relevant part of Valve's notification is the specific warning about expected social-engineering tactics. In the full quote reproduced by Digital Foundry, Valve warned: "They may quote your address back to you to prove they're genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to 'verify' your order. Treat all of them as fake."

"Expect fake messages - email, SMS or phone - that mention your hardware order and appear to come from Steam, Valve or a delivery company. They may quote your address back to you to prove they're genuine." — Valve, email to European customers (via Digital Foundry)

The combination of data — specific product, price paid, physical address, account-linked email — creates a detailed victim profile that far exceeds generic phishing. An attacker can cite the exact address, hardware model, and a plausible logistics pretext (customs, redelivery, order verification) to lower the victim's perceptual defenses. Valve explicitly advised against changing Steam passwords or account settings: the required action is not technical, but attentional.

CEVA's Response and the Designated Incident Contact

According to Valve's email, CEVA Logistics isolated affected systems, took involved resources offline, and launched an investigation with external investigators. Valve designated Artana Digital GmbH, based at Alstertwiete 3, 20099 Hamburg, Germany, as the specific point of contact for this breach. The company is also notifying competent data-protection authorities in the affected European countries.

The identity of the threat actors is not known at this time. The initial access vector against CEVA Logistics has not been disclosed, and no elements in the dossier confirm or rule out the presence of ransomware in the compromise. The exact number of affected customers has not been communicated by Valve or CEVA.

What to Do Now

  • Treat as suspicious all messages — email, SMS, or phone calls — that cite a Steam hardware order and request action on deliveries, payments, or account verifications, even if they correctly state your address
  • Do not change your Steam password or account settings: Valve explicitly stated this action is unnecessary for this specific incident
  • Reject any request to provide passwords or Steam Guard codes from parties claiming to be Steam support or couriers; Valve and official support never ask for them
  • Verify any dubious communications by contacting Valve directly through official Steam account channels, not via links or contacts provided in suspicious messages

The '90-Day Window' as Supply-Chain Risk Architecture

The incident fits a recurring pattern in hardware and retail: compromise of a third-party logistics provider exposes fulfillment data the primary vendor does not directly control. Sources in the dossier concurrently cite other recent episodes with analogous dynamics — Framework and Lidl are mentioned as comparable logistics breaches — suggesting this attack model is gaining systemic frequency in the European landscape.

CEVA's choice to limit retention to 90 days acts here as an automatic brake on potential damage, but also as a revealer: it defines exactly who is exposed and who is not, reducing uncertainty in notification. The case offers a reading on data governance in fulfillment contracts: the third-party vendor holds structural information to operate, and the duration of that holding determines the duration of residual post-breach risk. Valve could confine the notification thanks to this documented policy; without a formalized retention parameter, the compromise scope would have been potentially indeterminate.

The dossier does not specify whether contractual repercussions or revisions to the data-sharing model are underway between Valve and CEVA Logistics. It also remains to be verified whether the exfiltrated data has already been used in active phishing campaigns, or whether the current phase is still reconnaissance and preparation by threat actors.

Frequently Asked Questions

Do I need to change my Steam password?
No. Valve explicitly stated in the customer email that changing the password or account settings is not necessary. The compromised data does not include authentication credentials.

Which hardware products are affected?
Sources converge on Steam Machine, Steam Controller, and, according to Tom's Hardware and GG.deals, Steam Deck. The common criterion is physical hardware purchases shipped in Europe via CEVA Logistics within roughly the last 90 days.

Why did Valve learn of the incident with a delay?
Valve received notification from CEVA Logistics on August 7, 2026, six days after the attack ended (August 1). The dossier does not specify the reason for this latency, which may depend on CEVA's internal detection and confirmation timelines.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. tomshardware.com
  3. videocardz.com
  4. digitalfoundry.net
  5. gg.deals
  6. wccftech.com
  7. deals.bleepingcomputer.com