Valve Warns European Steam Hardware Buyers of Data Leak Linked to CEVA
Valve has informed multiple European customers who recently bought Steam hardware that their personal data may have been exposed in a cyberattack tied to delivery information used for shipments of devices like the Steam Deck, Steam Controller, and Steam Machine. The company says the compromised details were provided to its logistics partner CEVA for shipping purposes, and it is warning customers to be alert for scams that use their address and order context to look legitimate.
Key takeaways
- Valve emailed European buyers of recent Steam hardware after suspecting a data breach involving shipment data.
- The issue is linked to CEVA, the logistics company used to ship Steam Deck, Steam Controller, and Steam Machine in Europe.
- Valve says the delivery-related data CEVA handled may include full name, complete postal address, phone number, Steam account email, and the ordered product type and price.
- Valve states passwords, payment information, and Steam Guard codes were not affected because CEVA never had access to them.
- Valve urges customers to treat any message claiming to be from Steam, Valve, or a delivery company as fraudulent if it asks them to verify delivery, pay small fees, or log in.
- Valve says it is pressing CEVA for the full scope of the incident and notifying data protection authorities in the affected countries.
What happened and who may be affected
Valve contacted several European customers who purchased recent Steam hardware (including a Steam Deck, Steam Controller, or Steam Machine) after concluding their personal information was likely compromised during a cyberattack involving shipment data. Reports circulating on Reddit claim the incident affected CEVA, the logistics provider responsible for dispatching these products across Europe.
Valve says it learned on August 7 that some customer information was probably stolen. Valve provides CEVA with delivery data required to route shipments, and it is this delivery information that the attacker is believed to have obtained.
Because CEVA keeps delivery data for up to 90 days after an order is placed, Valve indicates that anyone who bought qualifying hardware within the last three months could be impacted.
Which data was at risk—and which wasn’t
Valve lists the types of information it believes may have been exposed. This includes the customer’s name, full postal address, phone number, the email address associated with their Steam account, and the type and price of the product that was ordered.
At the same time, Valve emphasizes that sensitive account and financial protections were not compromised. It says passwords, payment details, and Steam Guard codes were not affected, noting that CEVA never had access to those elements.
Valve’s scam warning and response from CEVA
In the email Valve sent, it warns customers to expect fake messages—via email, SMS, or phone calls—that reference their hardware shipment and appear to come from Steam, Valve, or a shipping company. Valve specifically notes that scammers may cite a customer’s address to make the messages look convincing, and they may try to push victims to confirm delivery, pay small customs or redelivery fees, or log in somewhere to “verify” an order.
Valve says no password change is necessary. It also reiterates that Steam Support does not handle account issues outside of its official site, and it does not request passwords or Steam Guard codes through phone calls or emails.
Valve adds that it is continuing to apply pressure on CEVA to determine the exact scope of the attack and that it is in the process of contacting data protection authorities in the countries affected. CEVA, for its part, is said to have isolated the systems involved, taken them offline, and hired external investigators to determine how the breach occurred.


