Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Valve Notifies Steam Hardware Customers of CEVA Logistics Data Breach
Valve Notifies Steam Hardware Customers of CEVA Logistics Data Breach
NEWS

Valve Notifies Steam Hardware Customers of CEVA Logistics Data Breach

Valve is notifying Steam hardware customers in Europe that hackers stole shipping and personal data after compromising its logistics partner CEVA Logistics between July 29 and August 1, 2026. No Steam account credentials or payment data were exposed, but the stolen PII creates a high-quality phishing dataset.

Dylan H.

News Desk

August 10, 2026
4 min read

Valve, the video game publisher and digital distribution giant behind Steam, is notifying Steam hardware customers in Europe that attackers accessed their personal shipping data after compromising CEVA Logistics, the company's European logistics and fulfillment partner. The breach represents a third-party supply chain incident — Valve's own systems were not compromised — but the stolen data creates meaningful downstream phishing and social engineering risks for affected customers.

What Happened

Attackers gained access to CEVA Logistics systems during a four-day window between July 29 and August 1, 2026. The breach was discovered by CEVA on August 7, and Valve began issuing customer notifications on August 10 — the same day this advisory was published.

CEVA Logistics is a subsidiary of the CMA CGM Group, one of the world's largest container shipping companies. It operates more than 1,000 warehouses globally and processed approximately 15 million shipments in 2025, generating $18.3 billion in annual revenue. The company handles Steam hardware fulfillment across European markets.

What Data Was Exposed

The attackers accessed CEVA systems that stored delivery-related customer records retained for up to 90 days post-order. The following categories of information were exposed for affected Steam hardware customers:

  • Customer names
  • Physical delivery addresses
  • Phone numbers
  • Email addresses
  • Product types ordered
  • Pricing information

What was NOT exposed: Steam account credentials, passwords, payment card data, Steam Guard codes, and all other Steam account information were not stored in CEVA's logistics systems and were not affected by this breach.

Why This Still Matters

Despite the absence of account or financial data, the combination of name, home address, phone number, email, and product details represents a high-quality targeting dataset for follow-on attacks. Valve explicitly warned affected customers to be vigilant about targeted phishing attempts that may reference their Steam hardware purchases to appear legitimate.

A threat actor with this data could craft convincing phishing emails impersonating Valve support, Steam hardware warranty claims, or CEVA delivery notifications — all personalized with accurate customer details. The specificity of the stolen information (product type, price) makes these lures significantly more convincing than generic phishing attempts.

Response Actions Taken

CEVA Logistics isolated the affected systems and took them offline following discovery. External cybersecurity investigators have been engaged to determine the full scope of the intrusion.

Valve stated it is actively pressing CEVA for the complete scope of the incident and is notifying data protection authorities in all affected European countries — indicating GDPR breach reporting obligations are in play. Under GDPR, organizations are required to notify supervisory authorities within 72 hours of becoming aware of a breach, and affected individuals must be notified without undue delay when the breach poses a high risk to their rights and freedoms.

What Affected Customers Should Do

If you are a Steam hardware customer in Europe who received a notification from Valve:

  1. Be skeptical of any email, SMS, or call referencing your Steam hardware purchase, delivery status, or account, particularly if it requests action, links, or credentials.
  2. Do not click links in unsolicited emails about Valve, Steam, or CEVA — navigate directly to the official site instead.
  3. Verify your Steam account security at store.steampowered.com (check active sessions, enable Steam Guard if not already active).
  4. Report suspicious contact to Valve's official support channels.

Your Steam account, passwords, and payment information are not at risk from this specific incident. The primary threat is personalized phishing leveraging your shipping information.

Broader Context

Third-party logistics breaches are an increasingly common vector for attackers targeting large consumer brands. Logistics partners process vast quantities of customer PII — names, addresses, phone numbers, order details — while often operating with less rigorous security controls than their enterprise clients. This incident is a reminder that your data security posture is only as strong as the weakest link in your vendor chain.

For organizations, this case reinforces the importance of vendor security assessments and contractual data retention minimization requirements — CEVA retains customer data for 90 days post-order, a window that significantly expands the pool of records at risk in any breach of their systems.

#data-breach#supply-chain#steam#valve#gdpr#phishing#third-party

Related Articles

Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw

Operation Klonen: Brazilian and German authorities arrest 7 suspects behind a €30M bank fraud exploiting a third-party payment processor vulnerability at Commerzbank.

4 min read

FBI: Hackers Using Social Engineering to Breach Accounts and Steal Explicit Content

The FBI warns hackers are breaching social media accounts to steal explicit content via credential stuffing, impersonation, and fake clone sites.

3 min read

Who Vets AI's Code? The Scale Challenge Facing Open Source Ingestion

With 85% of enterprises using AI coding tools but only 9% deploying AI-specific security controls, open source ingestion faces a critical vetting gap.

3 min read
Back to all News