Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics.
CEVA Logistics (a fully-owned subsidiary of the CMA CGM Group, the world’s third-largest shipping company) operates 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in revenues in 2025.
According to many reports on social media, affected Valve customers began receiving data breach notification emails earlier today.
In these emails, Valve said the attackers had access to CEVA Logistics’ servers between July 29 and August 1, which allowed them to gain access to information needed to ship hardware orders to Steam customers.
“Between July 29 2026 and August 1, 2026, a cyberattack hit CEVA Logistics, the company that ships Steam hardware to customers in Europe. CEVA is still investigating this attack, but as Valve learned on August 7, certain information about Steam customers, including you, was likely compromised,” Valve said.
“CEVA receives specific delivery-related information from Steam to be able to ship physical hardware to customers in Europe, and told us these are the details the attacker likely took. Because CEVA retains this information for up to 90 days after that order, we are sending this message to all customers we can assume were impacted.”
The stolen data includes the affected individuals’ names, addresses, phone numbers, email addresses, and the type and price of ordered products.
However, Valve added that no additional information related to the Steam account or other purchases was impacted, as CEVA does not have access to payment information, passwords, Steam Guard codes, or other sensitive data.
The company also warned affected Steam customers that they may be targeted by email, SMS, or voice phishing messages using the stolen information and impersonating Steam, Valve, or delivery companies.
“They may quote your address back to you to prove they’re genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to “verify” your order. Treat all of them as fake. You do not need to change your Steam password, and you don’t need to do anything to your account settings,” it added.
“We’re pressing CEVA for the full scope of what was taken and how, and we are in the process of notifying the data protection authorities in the countries affected, including yours. CEVA has isolated the affected systems, taken all offline and brought in outside investigators.”
Valve’s disclosure comes after CEVA Logistics informed multiple European retailers on August 1 that a cyberattack disrupted operations at eight of its European warehouses.
A Valve spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Canadian pleads guilty to Snowflake cloud data-theft attacks
Lidl discloses online shop breach after service provider hack
Insurance giant Aflac discloses data breach after subsidiary hack
Council of Europe investigates ShinyHunters data breach claims
Infinite Campus data breach affects 137,000 school staff accounts
Metabase SQLi zero-day exploited in customer data-theft attacks
Levi Strauss & Co. says hackers stole corporate data in cyberattack
North Carolina Ports confirms cyberattack disrupting operations
Webinar: Shadow AI in 2026 (and how attackers are taking advantage)
See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats
Spend four hours inside a fully-simulated underground with DARKROOM.
AI is a data-breach time bomb: Read the new report
See how Skyhigh Security’s patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



