Site icon TechloMedia

Valve Warns Steam Hardware Customers After Logistics Partner Suffers Cyberattack

Steam

Valve is warning some Steam hardware customers in Europe that their personal information may have been compromised after a cyberattack on its logistics partner CEVA Logistics.

The attack took place between July 29 and August 1, according to Valve. The company said it learned on August 7 that information belonging to some Steam hardware customers was likely compromised. CEVA is still investigating the incident, while external investigators are also auditing the attack.

The incident did not target Valve’s Steam systems directly. CEVA handles logistics for Steam hardware deliveries in Europe and receives customer information from Valve that is needed to ship physical products.

According to the notification sent to affected customers, the information that may have been accessed includes their name, street address, postal code, city, country, phone number and email address. The data may also include the type and price of the Steam hardware they ordered.

CEVA reportedly keeps this delivery information for up to 90 days after an order is assigned to it. This means the incident may affect customers whose hardware orders were being processed during that period, rather than only people whose packages were being delivered when the attack happened.

There is some good news for Steam users. CEVA does not have access to sensitive Steam account information such as passwords, payment details or Steam Guard authentication codes. Valve also says that other information connected to a customer’s Steam account or other purchases was not affected.

Valve is therefore not asking customers to change their Steam passwords or account settings. The bigger concern now is phishing and social engineering.

Someone with access to a customer’s name, address, email address and exact Steam hardware order could create a convincing scam. For example, an attacker could send an email or SMS pretending to be Valve or a delivery company and mention the customer’s actual order. They could then ask the customer to confirm a delivery, pay a small redelivery or customs fee, or sign in through a fake website.

This is why the leaked information could be more useful to scammers than a generic email list. An attacker who knows which Steam product someone ordered and where it is being delivered can make a fraudulent message look much more believable.

Valve is specifically warning customers to be suspicious of unexpected messages related to their Steam hardware delivery. Customers should not provide their Steam password, Steam Guard codes or payment information to anyone claiming to be a courier or Steam representative.

The company also says that legitimate Steam account support is handled through its official support system. Valve’s Steam support documentation lists Steam Support as the channel for payment and delivery problems.

The incident also shows a big security problem that is easy to overlook. A company does not need to suffer a direct breach for its customers to be affected. Third-party companies often receive names, addresses, phone numbers and order information to provide services such as shipping, payment processing and customer support. A breach at one of those companies can expose information originally collected by another company.

Valve appears to be pressing CEVA for more information about how the attack happened and exactly what data was taken. CEVA has reportedly taken affected systems offline to contain the incident, while external investigators are examining the attack. The investigation is still ongoing, so the full scope of the breach is not yet known.

This is also not the first time Steam users have faced confusion around a supposed major data breach. In 2025, reports claimed that data belonging to around 89 million Steam users had been leaked. Valve later said Steam itself had not been breached. The leaked material consisted of older SMS messages containing one-time codes and phone numbers, and did not include Steam passwords, payment information or information linking those phone numbers to Steam accounts.

The latest incident is different because Valve is directly warning affected hardware customers about a confirmed cyberattack at a third-party logistics provider and the possible exposure of their delivery information.

If you receive a message about a Steam hardware delivery, do not click the included login or payment link simply because it contains your real name, address or order details. Open Steam or type the official Steam website address yourself and check the order there. Also avoid sharing Steam passwords or Steam Guard codes with anyone.

Valve’s investigation should reveal how much data was actually taken and how the attackers gained access. Until then, customers should treat unexpected delivery-related messages as suspicious, even when the sender appears to know details about their Steam purchase.

Exit mobile version