Today, Valve has notified European customers that CEVA Logistics, the third-party company responsible for shippingSteam hardware across Europe, was targeted in a cyberattack between July 29 and August 1, 2026. Valve says it learned on August 7 (last Friday) that customer data was likely compromised as a result
What Was Exposed
Because CEVA needs delivery details to ship physical hardware, the attackers likely accessed a specific set of information tied to hardware orders, including:
- Full name
- Street address, postal code, and city
- Country
- Phone number
- Email address (the same one linked to the customer’s Steam account)
- The type and price of the ordered product
Valve emphasizes that account-level information was not affected. CEVA never had access to payment details, Steam passwords, Steam Guard codes, or any other Steam account data. Only customers with hardware orders placed in the past roughly 90 days (which is CEVA’s data retention window) are affected.
Standing Security Reminders
Still, Valve is warning affected users to expectphishing attempts appear legitimate, potentially quoting the victim’s own address back to them. These messages may ask for a “confirmation,” a small delivery or customs fee, or a login to “verify” the order. Valve says all such messages should be treated as fraudulent
Importantly, Valve states that customers do not need to change their passwords or adjust any account settings, since login credentials were not part of the breach.

Valve reiterated three permanent security facts for users:
- Steam Support only operates through help.steampowered.com, and never via email, Steam Chat, or Discord.
- Legitimate Steam pages only exist on store.steampowered.com, www.steampowered.com, steamcommunity.com, or help.steampowered.com. Users should type these manually rather than clicking links.
- Steam Support (and couriers) will never ask for a password or Steam Guard code.
Valve says it is pushing CEVA for a complete picture of the breach’s scope and method, and is in the process of notifying data protection authorities in all affected countries. CEVA has reportedly isolated the compromised systems, taken them offline, and brought in external investigators to assist with the response.
About the author: With over two decades of experience in gaming journalism, Alessio Palumbo has led the gaming vertical at Wccftech since August 2015. He started working at a young age for Italian websites like Everyeye.it, Gamestar.it, Nextgame.it, and Multiplayer.it before kickstarting the indie English-language publication Worlds Factory as its founder and Editor in Chief.
In the last decade, he has coordinated the overall output of Wccftech’s gaming section, managed PR relations, assigned reviews, produced daily news coverage, edited gaming content as needed, and delivered game reviews.
Arguably, his trademark content is the long series of exclusive developer interviews that have been cited by Wikipedia and by the biggest news media and gaming publications.
His passion for technology also makes him knowledgeable when it comes to gaming hardware and tech. His favorite genres include RPGs, MMORPGs, and action/adventure games.
Follow Wccftech on Google to get more of our news coverage in your feeds.
