Valve has confirmed that personal data belonging to European and UK hardware buyers was exposed in a cyberattack targeting its logistics partner, CEVA Logistics. The incident took place between July 29 and August 1, 2026. The attack compromised the third-party fulfillment provider responsible for regional hardware deliveries. Valve dispatched notification emails to affected customers on August 10 after CEVA formally confirmed the attack on August 7.
Key Takeaways
- The cyberattack compromised: a 90-day window of order fulfillment records held in external databases.
- You can watch: the handheld in action in the .
- The exposure impacts: customers who purchased devices directly through Steam across Europe and the UK over the past three months.
Scope of the Breach and Exposed Data
The cyberattack compromised a 90-day window of order fulfillment records held in external databases. The stolen dataset includes customer full names, physical delivery addresses, phone numbers, email addresses, and itemized hardware orders. Attackers also accessed exact purchase prices for high-value gear like the Valve Index VR Kit and Steam Deck OLED.
You can watch the handheld in action in the .
The exposure impacts customers who purchased devices directly through Steam across Europe and the UK over the past three months. However, Valve clarified that the breach occurred entirely within CEVA’s infrastructure.
Zero-Trust Isolation and Phishing Risks
Valve’s internal network successfully contained the threat. The company’s zero-trust architecture kept primary servers isolated from external fulfillment vendors. As a result, attackers compromised 0 passwords, payment card numbers, or Steam Guard authenticators.
The primary danger facing affected users is hyper-targeted spear-phishing. Scammers can now craft fraudulent SMS messages or emails posing as couriers like DPD, DHL, or Royal Mail. A scammer quoting a customer’s real address and demanding a fake customs fee for a €569 Steam Deck OLED poses an immediate threat.
Consequently, users should not reset their Steam passwords, as credentials remain safe. Instead, verify all shipping status requests directly through official Steam account purchase histories.
Supply Chain Trust and Community Reaction
For hardware enthusiasts, receiving physical gear directly from Valve is a cherished ritual. This breach disrupts a direct-to-consumer relationship built over years of global growth. This growth mirrors when Steam expanded regional currencies to international markets to better serve players everywhere.
Rather than panicking, the gaming community quickly rallied to organize grassroots defenses. Affected buyers across r/Steam and r/SteamDeck created public service threads to track scam vectors. Users are actively documenting incoming fraudulent texts, sharing notification screenshots, and warning fellow buyers about suspicious courier demands.
You can review reported scam attempts on the Did you receive a breach notification email from Valve regarding your recent hardware order? Share your experiences and any suspicious courier texts you have spotted in the comments section below!