Valve, the company behind the Steam gaming platform and Steam hardware line, has notified customers that a cyberattack exposed their personal information and hardware order details. The breach did not occur on Valve’s own systems, but on those of its shipping partner, CEVA Logistics, which handles delivery of Steam hardware such as the Steam Deck, Steam Controller, and Steam Machine.
Companies that share customer data with outside vendors and logistics partners have a responsibility to ensure those partners safeguard it, and to notify customers promptly when that trust is broken.
Valve’s Data Breach Investigation
According to reporting on the incident, Valve’s shipping partner CEVA Logistics suffered a cyberattack that exposed customer delivery data tied to Steam hardware purchases. Valve itself was not directly hacked, and the company has stated that passwords and payment information were not touched. Instead, the exposure involved shipping and order-related information that CEVA stores for approximately 90 days after a shipment, meaning any European customer who received a Steam Deck, Steam Controller, or Steam Machine within roughly the past three months could be affected.
Valve learned of the incident on August 7, 2026, and began notifying affected customers three days later, on August 10. As of this report, neither Valve nor CEVA Logistics has disclosed the exact number of customer records involved. Separately, Dutch retailers Bol and De Bijenkorf reportedly were told about the same CEVA incident around August 1, 2026, and issued their own customer warnings, suggesting the breach’s impact extended beyond Valve’s own customer base to other companies that use CEVA for logistics.
Breaches involving third-party logistics and shipping vendors are a growing concern because delivery data, while it may seem less sensitive than financial or medical records, gives scammers exactly what they need to craft highly convincing phishing attempts: a real name, a real address, and a real product a person actually purchased. This kind of targeted phishing built around a genuine, recent transaction is often far more effective than generic scam messages because it exploits the recipient’s own recent purchase history to appear legitimate. Security researchers have also noted a broader trend of shipping and delivery data being actively traded on dark web marketplaces, making this type of breach increasingly attractive to cybercriminals even when core financial data is not exposed.
Valve has faced security concerns in the past. In May 2025, a threat actor attempted to sell what was claimed to be a dataset of tens of millions of Steam user records, though that data reportedly turned out to be older, already-expired authentication codes routed through a third party Valve says it never partnered with. Valve also suffered a direct breach in November 2011 that exposed records for millions of users, including usernames, emails, and encrypted payment card details. The current CEVA-related incident is distinct from both of those prior events, as it involves a shipping partner’s systems rather than Valve’s own infrastructure.
When Did This Breach Occur?
The attack on CEVA Logistics’ systems is reported to have occurred between July 29 and August 1, 2026. Valve states it learned of the incident on August 7, 2026, and began sending notification emails to affected customers on August 10, 2026, roughly nine days after the breach window closed and three days after Valve itself was informed.
What Information Was Breached?
The exposed information reportedly includes customers’ full names, street addresses, postal codes, cities, countries, phone numbers, the email address linked to their Steam account, and details about the type and price of the hardware they ordered. Valve has stated that passwords and payment card information were not part of the exposure. The affected population appears to be limited to European customers who purchased Steam hardware, such as a Steam Deck, Steam Controller, or Steam Machine, within approximately the last three months, since that is how long CEVA retains delivery records after a shipment.
What You Can Do
If you purchased Steam hardware and shipped it to a European address within the past few months, Valve and security researchers recommend the following:
- Treat any unsolicited email, text message, or phone call referencing your recent Steam hardware order as a likely scam, even if it correctly states your name, address, or order details
- Remember that Steam Support never contacts users through email, Steam Chat, or Discord, and only handles account issues through its official help page
- Do not click links or provide payment information in response to a message asking you to pay a customs fee, confirm a delivery, or update your order
- Enable Steam Guard two-factor authentication and use a strong, unique password on your account as a general precaution
- Report any suspicious messages referencing your Steam order to Valve through official channels
File a Data Breach Lawsuit Against Valve
Attorneys are investigating whether a class action lawsuit can be filed on behalf of individuals whose personal information was exposed in the Valve/CEVA Logistics data breach. If a breach is confirmed to have resulted from inadequate data security practices by Valve or its vendor, affected individuals may be entitled to compensation for their losses, including the time and expense associated with monitoring their accounts and guarding against identity theft or targeted phishing.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.