
Valve warns Steam hardware buyers after CEVA Logistics breach
A cyberattack on Valve's European distribution partner CEVA Logistics exposed names, addresses, emails, and phone numbers of Steam hardware customers. Valve says account data and payment info were not affected.
What happened
Valve has begun notifying customers in Europe that their personal data may have been exposed following a cyberattack on CEVA Logistics, the company Valve used to distribute Steam hardware in the region. The affected customers are those who ordered products like the Steam Machine or Steam Controller.
According to the email Valve sent out, as shared on Reddit by user ‘nelsonsflagship’ and several other recipients, Valve first learned of the breach on August 7. The attack appears to have taken place between July 29 and August 1. “CEVA is still investigating this attack, but as Valve learned on August 7, certain information about Steam customers, including you, was likely compromised,” the email reads.
The information at risk includes names, physical addresses, email addresses, and phone numbers. These are standard shipping details that Valve passed along to CEVA to fulfill hardware orders.
What was not exposed
Valve was clear on one point that will matter most to Steam users: the breach does not extend to your actual Steam account. The company stated that CEVA did not have access to payment information, passwords, Steam Guard codes, or anything else tied to purchases beyond the specific hardware order.
“Additional information related to your Steam account or other purchases was not impacted,” the email continued. So while the exposure is real and worth taking seriously, it is limited to the logistics side of the transaction rather than the platform itself.
That said, the attackers do have the email addresses associated with affected Steam accounts. That is enough to enable convincing phishing attempts, which is exactly what Valve is warning people about.
What to watch out for
Valve’s guidance is straightforward: be skeptical of any unsolicited emails or text messages that claim to be about your Steam hardware order. Attackers who have your name, address, phone number, and email address can craft messages that look surprisingly plausible. A fake delivery notification, a spoofed shipping update, a message asking you to confirm order details, all of those are the kind of follow-up a bad actor might attempt with this data.
If you received Valve’s warning email and are not sure whether a follow-up message is legitimate, the safest approach is to go directly to Steam rather than clicking any links.
Rough timing for Steam Machine owners
The breach is an unfortunate wrinkle for a group of customers who have already had a bumpy experience. As reported by Dexerto, the Steam Machine faced delays before reaching buyers, and when it did go on sale in Japan, it sold out within three hours. Demand was clearly there. Getting a data breach notice shortly after finally receiving your hardware is not the welcome-to-the-ecosystem moment Valve would have hoped for.
CEVA Logistics is described as still actively investigating the incident. Valve has not announced whether it plans to change distribution partners or what additional steps, if any, it will take on behalf of affected customers. Anyone who believes their information has been misused should also consider reporting the incident to their country’s relevant data protection authority, particularly given that this involves residents in Europe.
What personal data was leaked in the Steam hardware breach?
According to Valve's email to affected customers, the attacker likely obtained names, addresses, email addresses, and phone numbers that were submitted as part of hardware orders.
Was my Steam account password or payment info exposed?
Valve says no. The company stated that CEVA Logistics did not have access to payment information, passwords, Steam Guard codes, or other account-related details.
Who was affected by the CEVA Logistics cyberattack?
Based on Valve's communications, the breach affected customers in Europe who ordered Steam hardware such as the Steam Machine and Steam Controller through CEVA Logistics.
What should affected Steam hardware customers do now?
Valve has advised customers to stay alert for suspicious emails or text messages that appear to be about their order, as attackers may attempt phishing using the compromised contact details.
