Valve Warns Steam Hardware Customers After Cyberattack on Logistics Partner

partner-distribuzione-dell-hardware-steam-f845

Valve has warned European Steam hardware customers that a cyberattack targeting its logistics partner may have exposed some personal information connected to recent orders. The company says no payment or account-security data was accessed, but it is urging users to watch for phishing scams that could reference their hardware shipment.

Attack timeline and the logistics company involved

  • Valve says European partners responsible for distributing Steam hardware (including Steam Machine and Steam Controller) were affected by a cyberattack.
  • The incident occurred between July 29 and August 1, 2026.
  • CEVA Logistics, the company managing Steam hardware shipping in Europe, was identified as the organization involved.
  • CEVA reported the issue to Valve on August 7 after initial internal checks.
  • Valve believes the attack may have led to the possible exposure of some customers’ personal data.

What information may have been exposed

In an email sent to affected users, Valve said the attackers accessed data used exclusively for delivering Steam hardware.

  • Possible exposed details include: customer name, full address, country, phone number, and the email associated with the user’s Steam account.
  • The records may also include the hardware product type purchased and its price.
  • Valve says sensitive information was not exposed, including payment details, passwords, Steam Guard codes, or other account-security elements.
  • Valve adds that CEVA does not have access to those account and payment/security data categories.

Valve noted that CEVA keeps delivery-related data for up to 90 days from the time an order is placed—one reason the notification covers customers who may fall within that window.

Valve’s guidance: how to spot phishing and fake delivery messages

Even without account passwords or payment data being involved, Valve cautioned that scammers could use the information they obtained to make fraudulent messages look more convincing.

  • Valve warns of phishing attempts via email, SMS, or phone calls that reference the hardware order.
  • Fraud messages could appear to come from Steam, Valve, or shipping carriers.
  • Scammers may try to push users to confirm deliveries, pay supposed customs fees, or visit fraudulent websites.

Valve also provided three key rules to help customers identify scams:

  • Steam Support communications only operate through help.steampowered.com.
  • Legitimate Steam login pages exist only on official Steam domains.
  • No Steam representative or shipping carrier will ever request a Steam password or Steam Guard code.

Response steps by Valve and CEVA

  • Valve says it requested full clarification from CEVA about the incident.
  • Valve also initiated notifications to data protection authorities in the affected countries.
  • CEVA isolated the compromised systems.
  • CEVA brought in external investigators to support the response.