“Report: Personal Information of Steam Users Compromised in Cyberattack on Valve Partner”

"Report: Personal Information of Steam Users Compromised in Cyberattack on Valve Partner"

### Cyberattack on CEVA Logistics: Potential Personal Data Breach for Steam Customers in Europe

In late July through early August 2026, a significant cyberattack targeted CEVA Logistics, a shipping partner for Valve’s Steam platform, potentially compromising the personal information of customers in Europe who purchased hardware during that time frame.

According to a communication from Valve, which was made public by sources such as Gaming On Linux and Reddit users, the breach occurred from July 29 to August 1, 2026. The email from Valve indicated that CEVA Logistics was still in the process of investigating the attack but had discovered that customer data, including names, phone numbers, emails, and postal addresses, might have been affected.

CEVA retains this information for a maximum of 90 days post-order, meaning that anyone who purchased Steam hardware within that window could potentially be at risk. However, Valve assured customers that if they received a notification about the incident, it did not necessarily mean their data had been compromised; Valve opted to contact those customers who were deemed likely impacted by the cyberattack.

Fortunately, customers do not need to worry about their payment information being compromised, as CEVA has no access to payment data, passwords, Steam Guard codes, or similar sensitive information. This announcement aims to alleviate concerns regarding financial safety, which is often a primary worry during data breaches.

For individuals whose information may have been exposed, the email provides cautionary advice: expect an influx of phishing attempts pretending to be from Steam, Valve, or delivery companies. These can manifest as emails, text messages, or phone calls referencing hardware orders, often including personal information to appear legitimate. Common tactics may involve requests to confirm deliveries, pay small fees, or login to verify orders. Valve’s communication underscores the importance of treating these messages as fraudulent and advises against clicking on links in suspicious emails.

Additionally, Valve emphasized that legitimate support requests would never be handled through email, Steam chat, or Discord, encouraging customers to verify any correspondence critically. They advised that customers should navigate to the official Steam site directly, rather than through potentially deceptive links.

To address growing concerns, Valve assured customers they are pressing CEVA for clearer information regarding the breach’s scope. They also mentioned that they are in the process of notifying data protection authorities in the affected countries.

The unsettling situation raises questions about the integrity of communication from companies facing cyber threats, as it is essential for consumers to remain vigilant against possible scams that could exploit their personal information. Despite the challenges posed by such breaches, Valve’s transparent communication aims to help customers navigate this precarious situation while reinforcing the importance of cybersecurity awareness.

In light of this incident, those in Europe who recently purchased Steam hardware should remain cautious and proactive about securing their personal information and remain skeptical of unsolicited communications relating to their orders.