Were you recently affected by a data breach?

Valve Data Breach

Valve, the company behind the Steam gaming platform, has notified customers that a cyberattack on its shipping partner CEVA Logistics exposed names, addresses, phone numbers, and Steam order details for hardware buyers in Europe.

Valve
Date of Breach: July 29, 2026 - August 1, 2026
CAU logo

Who was affected:

Clients of Valve

Impacted Data:

Names, street addresses, postal codes, cities, countries, phone numbers, Steam account email addresses, hardware order type and price

Valve, the company behind the Steam gaming platform and Steam hardware line, has notified customers that a cyberattack exposed their personal information and hardware order details. The breach did not occur on Valve’s own systems, but on those of its shipping partner, CEVA Logistics, which handles delivery of Steam hardware such as the Steam Deck, Steam Controller, and Steam Machine.

Companies that share customer data with outside vendors and logistics partners have a responsibility to ensure those partners safeguard it, and to notify customers promptly when that trust is broken.

Valve’s Data Breach Investigation

According to reporting on the incident, Valve’s shipping partner CEVA Logistics suffered a cyberattack that exposed customer delivery data tied to Steam hardware purchases. Valve itself was not directly hacked, and the company has stated that passwords and payment information were not touched. Instead, the exposure involved shipping and order-related information that CEVA stores for approximately 90 days after a shipment, meaning any European customer who received a Steam Deck, Steam Controller, or Steam Machine within roughly the past three months could be affected.

Valve learned of the incident on August 7, 2026, and began notifying affected customers three days later, on August 10. As of this report, neither Valve nor CEVA Logistics has disclosed the exact number of customer records involved. Separately, Dutch retailers Bol and De Bijenkorf reportedly were told about the same CEVA incident around August 1, 2026, and issued their own customer warnings, suggesting the breach’s impact extended beyond Valve’s own customer base to other companies that use CEVA for logistics.

Breaches involving third-party logistics and shipping vendors are a growing concern because delivery data, while it may seem less sensitive than financial or medical records, gives scammers exactly what they need to craft highly convincing phishing attempts: a real name, a real address, and a real product a person actually purchased. This kind of targeted phishing built around a genuine, recent transaction is often far more effective than generic scam messages because it exploits the recipient’s own recent purchase history to appear legitimate. Security researchers have also noted a broader trend of shipping and delivery data being actively traded on dark web marketplaces, making this type of breach increasingly attractive to cybercriminals even when core financial data is not exposed.

Valve has faced security concerns in the past. In May 2025, a threat actor attempted to sell what was claimed to be a dataset of tens of millions of Steam user records, though that data reportedly turned out to be older, already-expired authentication codes routed through a third party Valve says it never partnered with. Valve also suffered a direct breach in November 2011 that exposed records for millions of users, including usernames, emails, and encrypted payment card details. The current CEVA-related incident is distinct from both of those prior events, as it involves a shipping partner’s systems rather than Valve’s own infrastructure.

When Did This Breach Occur?

The attack on CEVA Logistics’ systems is reported to have occurred between July 29 and August 1, 2026. Valve states it learned of the incident on August 7, 2026, and began sending notification emails to affected customers on August 10, 2026, roughly nine days after the breach window closed and three days after Valve itself was informed.

What Information Was Breached?

The exposed information reportedly includes customers’ full names, street addresses, postal codes, cities, countries, phone numbers, the email address linked to their Steam account, and details about the type and price of the hardware they ordered. Valve has stated that passwords and payment card information were not part of the exposure. The affected population appears to be limited to European customers who purchased Steam hardware, such as a Steam Deck, Steam Controller, or Steam Machine, within approximately the last three months, since that is how long CEVA retains delivery records after a shipment.

What You Can Do

If you purchased Steam hardware and shipped it to a European address within the past few months, Valve and security researchers recommend the following:

  • Treat any unsolicited email, text message, or phone call referencing your recent Steam hardware order as a likely scam, even if it correctly states your name, address, or order details
  • Remember that Steam Support never contacts users through email, Steam Chat, or Discord, and only handles account issues through its official help page
  • Do not click links or provide payment information in response to a message asking you to pay a customs fee, confirm a delivery, or update your order
  • Enable Steam Guard two-factor authentication and use a strong, unique password on your account as a general precaution
  • Report any suspicious messages referencing your Steam order to Valve through official channels

File a Data Breach Lawsuit Against Valve

Attorneys are investigating whether a class action lawsuit can be filed on behalf of individuals whose personal information was exposed in the Valve/CEVA Logistics data breach. If a breach is confirmed to have resulted from inadequate data security practices by Valve or its vendor, affected individuals may be entitled to compensation for their losses, including the time and expense associated with monitoring their accounts and guarding against identity theft or targeted phishing.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 2026 (reported via dark web leak site claim; not confirmed by the company)
Date of Breach: Not publicly disclosed as of August 2026
Date of Breach: May 4, 2026 (date of discovery)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.