Valve has alerted European customers that their personal shipping information may have been exposed in a recent security incident. This matters because the breach affects buyers of Steam Deck and other hardware, potentially leaving their home addresses and contact details in the hands of attackers. Users who ordered devices in the last three months should treat their private data as compromised until they take protective steps.
Valve notifies European customers that shipping partner CEVA Logistics suffered a cyberattack exposing personal data
The vulnerability stems from a cyberattack on CEVA Logistics, the third-party shipping partner Valve uses to deliver orders. The attack window occurred between July 29 and August 1, 2026, according to Valve's notification. The incident underscores the potential vulnerabilities associated with entrusting third-party logistics partners with the management of sensitive customer data.
Compromised data includes names, physical addresses, phone numbers, email addresses, and specific order details. These records cover hardware purchases made within the last 90 days. Valve confirmed that Steam account credentials, passwords, and payment details were not part of the stolen dataset.
Valve is actively notifying data protection authorities in the countries affected by the breach. The company also warns customers to watch for phishing emails that reference the incident. Users should verify any communications claiming to be from Valve by checking official Steam domains directly.
This incident represents a targeted breach of Valve's logistics chain rather than a direct hack of Steam's core servers. The company is managing the fallout by informing authorities and advising users on verification practices. European hardware buyers should monitor their inboxes for official guidance and remain cautious of unsolicited messages.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.