Valve, the video game publisher and digital distribution giant behind Steam, is notifying Steam hardware customers in Europe that attackers accessed their personal shipping data after compromising CEVA Logistics, the company's European logistics and fulfillment partner. The breach represents a third-party supply chain incident — Valve's own systems were not compromised — but the stolen data creates meaningful downstream phishing and social engineering risks for affected customers.
What Happened
Attackers gained access to CEVA Logistics systems during a four-day window between July 29 and August 1, 2026. The breach was discovered by CEVA on August 7, and Valve began issuing customer notifications on August 10 — the same day this advisory was published.
CEVA Logistics is a subsidiary of the CMA CGM Group, one of the world's largest container shipping companies. It operates more than 1,000 warehouses globally and processed approximately 15 million shipments in 2025, generating $18.3 billion in annual revenue. The company handles Steam hardware fulfillment across European markets.
What Data Was Exposed
The attackers accessed CEVA systems that stored delivery-related customer records retained for up to 90 days post-order. The following categories of information were exposed for affected Steam hardware customers:
- Customer names
- Physical delivery addresses
- Phone numbers
- Email addresses
- Product types ordered
- Pricing information
What was NOT exposed: Steam account credentials, passwords, payment card data, Steam Guard codes, and all other Steam account information were not stored in CEVA's logistics systems and were not affected by this breach.
Why This Still Matters
Despite the absence of account or financial data, the combination of name, home address, phone number, email, and product details represents a high-quality targeting dataset for follow-on attacks. Valve explicitly warned affected customers to be vigilant about targeted phishing attempts that may reference their Steam hardware purchases to appear legitimate.
A threat actor with this data could craft convincing phishing emails impersonating Valve support, Steam hardware warranty claims, or CEVA delivery notifications — all personalized with accurate customer details. The specificity of the stolen information (product type, price) makes these lures significantly more convincing than generic phishing attempts.
Response Actions Taken
CEVA Logistics isolated the affected systems and took them offline following discovery. External cybersecurity investigators have been engaged to determine the full scope of the intrusion.
Valve stated it is actively pressing CEVA for the complete scope of the incident and is notifying data protection authorities in all affected European countries — indicating GDPR breach reporting obligations are in play. Under GDPR, organizations are required to notify supervisory authorities within 72 hours of becoming aware of a breach, and affected individuals must be notified without undue delay when the breach poses a high risk to their rights and freedoms.
What Affected Customers Should Do
If you are a Steam hardware customer in Europe who received a notification from Valve:
- Be skeptical of any email, SMS, or call referencing your Steam hardware purchase, delivery status, or account, particularly if it requests action, links, or credentials.
- Do not click links in unsolicited emails about Valve, Steam, or CEVA — navigate directly to the official site instead.
- Verify your Steam account security at store.steampowered.com (check active sessions, enable Steam Guard if not already active).
- Report suspicious contact to Valve's official support channels.
Your Steam account, passwords, and payment information are not at risk from this specific incident. The primary threat is personalized phishing leveraging your shipping information.
Broader Context
Third-party logistics breaches are an increasingly common vector for attackers targeting large consumer brands. Logistics partners process vast quantities of customer PII — names, addresses, phone numbers, order details — while often operating with less rigorous security controls than their enterprise clients. This incident is a reminder that your data security posture is only as strong as the weakest link in your vendor chain.
For organizations, this case reinforces the importance of vendor security assessments and contractual data retention minimization requirements — CEVA retains customer data for 90 days post-order, a window that significantly expands the pool of records at risk in any breach of their systems.