Steam hardware customers in Europe may have had personal information compromised following a cyberattack against CEVA Logistics, the company responsible for shipping Steam hardware to customers in the region. The attack took place between July 29 and August 1, 2026, with Valve learning on August 7 that some customer information was likely affected.
CEVA is continuing to investigate the incident. According to Valve, the logistics company receives delivery information from Steam that is required to fulfil physical hardware orders and retains that information for up to 90 days after an order.
The information potentially exposed includes customers’ names, street addresses, postal codes, cities, countries, phone numbers and email addresses. The type and price of the Steam hardware ordered may also have been compromised.
Valve stressed that other Steam account information and purchases were not affected. CEVA does not have access to customers’ payment information, passwords or Steam Guard codes.
Valve is now contacting customers who may have been affected by the incident. The company is also warning them to be particularly cautious about messages that appear to relate to their hardware orders.
Valve Warns Customers About Scams
The compromised delivery information could make subsequent phishing attempts more convincing. Valve expects affected customers may receive fraudulent emails, SMS messages or phone calls that reference their hardware purchase and appear to come from Steam, Valve or a delivery company.
These messages could include genuine personal information such as a customer’s address. Valve warned that scammers may use this information to request confirmation of a delivery, ask for a small customs or redelivery payment, or direct customers to a fake website to verify their order.
Valve said customers do not need to change their Steam passwords or modify their account settings as a result of the incident.
Valve further stated that Steam Support will never request a user’s password or Steam Guard code. The company said couriers will not request these details either.
CEVA Investigation Is Ongoing
Valve said it is pressing CEVA for more information about what data was taken and how the attack occurred. The company is also preparing to notify data protection authorities in the affected countries.
CEVA has isolated the affected systems, taken them offline and brought in external investigators as it continues investigating the cyberattack.
Customers with questions about the incident can contact Valve through help.steampowered.com. Valve has also provided Artana Digital GmbH in Hamburg, Germany, as a designated contact point for further information about the incident.

