ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Valve notifies Steam Hardware customers after logistics partner breach

Valve Corporation has notified Steam hardware customers in Europe that cybercriminals stole their data after breaching the internal network of its shipping partner, CEVA Logistics.

 

Valve Corporation designs and manufactures Steam hardware, including the Steam Deck, Steam Machine, Steam Controller, and Steam Frame VR headset, running on SteamOS and supported by its Proton software layer. In Europe, CEVA Logistics serves as Valve’s third-party shipping and fulfillment partner, handling hardware deliveries to customers.

 

Recently, Valve has started notifying its customers of a data security incident where threat actors breached CEVA Logistics’ internal network between July 29 and August 1 and gained access to information used to fulfill and ship Steam hardware orders.

 

“Hello, Between July 29 2026 and August 1, 2026, a cyberattack hit CEVA Logistics, the company that ships Steam hardware to customers in Europe. CEVA is still investigating this attack, but as Valve learned on August 7, certain information about Steam customers, including you, was likely compromised,” Valve said.

 

The compromised data included names, addresses, phone numbers, email addresses that are registered with Steam accounts, the type and price of the ordered product and more.

 

“CEVA receives specific delivery-related information from Steam to be able to ship physical hardware to customers in Europe, and told us these are the details the attacker likely took. Because CEVA retains this information for up to 90 days after that order, we are sending this message to all customers we can assume were impacted.

 

“Additional information related to your Steam account or other purchases was not impacted. CEVA does not have access to your payment information, passwords, Steam Guard codes or other information,” Valve added.

 

Valve’s disclosure follows a cyber attack between July 29 and August 1 that affected eight CEVA Logistics warehouses in Europe, disrupting order processing for retail customers and exposing shoppers’ personal information.

 

CEVA, a third-party logistics provider operating more than 1,000 warehouses worldwide, said the breach was limited to the eight facilities and did not affect its wider operations. Air, ocean, ground, and rail transportation services continued without disruption. CEVA has not publicly commented on the incident, which is being investigated by the Dutch Data Protection Authority, other law enforcement agencies, and the companies involved.

 

Other prominent organisations affected by the data security incident included Bol, De Bijenkorf, ING, Ajax, and Ace & Tate, highlighting the breach’s wider impact across retail, banking, sports, and e-commerce.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543