Aiignitions
Tech News

Valve Warns Steam Hardware Buyers After Shipping Partner CEVA Is Hacked

Valve is emailing European Steam hardware buyers after a breach at shipping partner CEVA Logistics exposed names, addresses and order details. What leaked and what to do.

Valve Warns Steam Hardware Buyers After Shipping Partner CEVA Is Hacked

What happened

Valve has started emailing Steam hardware customers across Europe to tell them their personal data was likely stolen. The leak did not come from Steam. It came from CEVA Logistics, the third-party company Valve uses to ship physical hardware to European buyers.

According to Valve's notice, attackers had access to CEVA's servers between July 29 and August 1, 2026. Valve was informed on August 7 that customer data tied to hardware orders had probably been taken, and began sending direct security emails shortly after. The affected products are the ones Valve ships as boxes rather than downloads: the Steam Deck, the second-generation Steam Machine that went on sale on June 29, 2026, and the 2026 Steam Controller.

Valve's second-generation Steam Machine, one of the hardware products whose shipping records were exposed in the CEVA breach

To be clear about the boundary: Steam itself was not breached, and there is no sign anyone touched Valve's own systems. What leaked is the parcel-delivery paperwork a courier needs to get a box to your door.

What leaked, and what didn't

Valve says the exposed records may include your full name, street address, postal code, city and country, phone number, the email address linked to your Steam account, and the type and price of the hardware you ordered. CEVA keeps this shipping data for up to 90 days after an order, so recent buyers are the ones most likely to be caught.

What did not leak matters just as much. Valve was explicit that the incident does not touch your payment information, passwords, Steam Guard codes or any other account credentials, for the simple reason that CEVA never had access to them. A courier is handed a name and an address to make a delivery, not a payment card or a login. So there is no need to change your Steam password or reset Steam Guard because of this.

The 2026 Steam Controller, part of the Steam hardware lineup shipped through CEVA Logistics in Europe

That split is the whole story. On paper it is a low-severity breach, no financial data and nothing that unlocks an account. In practice it is a clean, verified list of gamers, their home addresses and exactly what expensive electronics just arrived there, which is a different kind of problem.

The breach behind the breach

Valve is not the only name on the victim list, and it is arguably the smallest. CEVA Logistics is a contract-logistics arm of CMA CGM, the world's third-largest container shipping group. CEVA reported roughly $18.3 billion in revenue in 2025, runs around 1,000 warehouses and moved about 15 million shipments last year. The intrusion hit at least eight of its European warehouses; CEVA says no other systems globally were affected.

CEVA Logistics logo — the CMA CGM shipping subsidiary at the centre of the breach

Because so many retailers outsource fulfilment to the same handful of logistics firms, one break-in spills across dozens of unrelated brands. Reporting on the CEVA incident names Dutch retailers Bol and De Bijenkorf, eyewear brand Ace & Tate, football club Ajax and banking group ING among those affected, and the Dutch data protection authority said it had received breach reports from ten organisations tied to the event. As of August 14, 2026 no group has publicly claimed the attack, and CEVA has declined to say whether it received a ransom demand.

Why shipping data is dangerous

Payment breaches get the headlines, but a shipping leak is often more useful to a scammer, and this one is unusually complete. A criminal now has a genuine name, a real delivery address, a working phone number and email, and the exact item and price of a recent order. That is everything needed to write a message a target has no obvious reason to doubt.

Valve spelled out the playbook in its own notice. "They may quote your address back to you to prove they're genuine," the company warned. "They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to 'verify' your order. Treat all of them as fake." A fake "your Steam Deck is held at customs, pay €2 to release it" text lands very differently when it names the device you actually bought and the address it is going to.

Chart showing common causes of data breaches, illustrating how third-party and supply-chain compromises expose customer data

This is the recurring shape of a supply-chain breach. The company holding your data is not the one you handed it to, the leaked fields look harmless one by one, and the damage shows up weeks later as a delivery scam rather than a drained bank account.

What Steam hardware owners should do

If you bought a Steam Deck, Steam Machine or Steam Controller for delivery in Europe recently, assume your shipping details are out and act on that basis:

  • Distrust any unexpected message about a delivery, even one that quotes your correct address or order. Knowing your details is now proof of nothing.
  • Never pay a "customs," "redelivery" or "release" fee from a link in a text or email. Legitimate couriers do not collect surprise fees this way.
  • Verify only through official channels. Check order status inside Steam or on the carrier's own website that you typed in yourself, not through a link you were sent.
  • You do not need to change your Steam password or Steam Guard. Those were not exposed. Do the opposite and treat any message telling you to "reset" them as the scam.

Valve says it is notifying the data protection authorities in each affected country, so more country-specific guidance may follow.

What's next

The immediate risk is a wave of phishing and smishing that will trail this breach for weeks, timed to look like delivery follow-ups. Expect it to peak while orders from the summer hardware launches are still in transit or freshly delivered.

The larger question is about CEVA, not Valve. A single compromise of one logistics contractor reached across banks, retailers, a football club and a games company at once, and regulators in the Netherlands and elsewhere will be examining how one courier's network held that much customer data behind defences that failed. For shoppers, the uncomfortable takeaway is that you can do everything right at checkout and still have your details leaked by a company you never chose and may never have heard of.

Read the original source

Head to the original source for the full announcement and complete details.

Read Original Source