Skip to main content
GameDev.net gamedev.net

PRO Tired of ads? Read GameDev.net ad-free and help keep the community independent with GameDev Pro — $3/month.

GamesIndustry.biz
GamesIndustry.biz
· 1 month, 2 weeks ago • Vikki Blake

Valve confirms Steam hardware buyers' data exposed in CEVA Logistics cyberattack

Briefing

Valve has started notifying European customers who ordered Steam hardware that their personal data may have been exposed after a cyberattack on CEVA Logistics, the company handling regional deliveries. The breach hit CEVA between July 29 and August 1, and Valve learned about it on August 7.

The exposed data can include names, street addresses, postal codes, cities, countries, phone numbers, the email address tied to a Steam account, and the type and price of hardware ordered. Valve says the affected group is likely centered on buyers of Steam Deck, Steam Machine, and Steam Controller hardware, though the exact number of customers has not been disclosed.

For developers, the immediate takeaway is less about Steam accounts being compromised and more about the phishing risk that follows a logistics breach. Valve says no passwords, Steam Guard codes, or payment details were exposed, and it is not asking customers to change account credentials. Even so, attackers can use real order data to make email, SMS, or phone scams look convincing.

CEVA says the intrusion affected part of its European contract logistics operations and disrupted at least eight warehouses. Valve is pressing for more detail and notifying data protection authorities in the affected countries. If you ship hardware, collector editions, or any physical goods tied to account data, this is another reminder that the weakest link is often the fulfillment chain, not the platform itself.

“Steam Support only operates through help.steampowered.com.”

— Valve · Valve reminding customers how to avoid phishing scams
At a glance
what
Valve is notifying European Steam hardware buyers that personal data may have been exposed in a CEVA Logistics cyberattack.
who
Valve, CEVA Logistics, and affected Steam hardware customers in Europe.
when
CEVA was breached between July 29 and August 1; Valve learned on August 7.
impact
Exposed order/contact data can fuel convincing phishing attempts, though passwords and payment data were not affected.
Signal Concerning

Customer data exposure and phishing risk are the core issues.

Discuss

Follow Steam updates

See relevant stories in your personalized news feed.

Sign in to follow

Continue on GameDev.net

Useful next steps related to this story.

Game development news without the noise

One useful weekly briefing. No daily flood.

Sending your confirmation email…

Discussion

Loading comments...