August 10, 2026: Valve is emailing European Steam hardware customers that a cyberattack on shipper CEVA Logistics between July 29 and August 1 likely exposed their delivery data — names, addresses, phones, emails, and what they ordered. Steam passwords and payment cards were not in CEVA’s systems, Valve says. Change nothing on your Steam account. Treat every “customs fee” text as fake.
If you bought a Steam Deck, Index kit, or other Steam hardware that ships through Europe in the last ~90 days, this notice is about you even if you never heard CEVA’s name on the packing slip.
What happened
CEVA Logistics runs contract warehouses that pack and ship physical goods for brands across Europe. Valve uses CEVA to deliver Steam hardware to European customers. Attackers reached CEVA servers in a window Valve dates to July 29 through August 1, 2026. Valve learned on August 7 and started customer emails on August 10.
CEVA confirmed the intrusion to TechCrunch: a cyber incident impacting part of its European contract logistics operations, limited to eight warehouses, with other global CEVA systems unaffected. The company said it activated security protocols, launched an investigation that is still ongoing, and is working with authorities. Some affected applications were coming back online.
This is the same European logistics wave that already produced warnings from Bol, De Bijenkorf, Ajax, ING’s loyalty shop, and Ace & Tate. The Dutch data protection authority told TechCrunch it had received breach reports from 10 organisations tied to the incident.
What Valve says was taken
CEVA holds only what it needs to put a box on a doorstep. Per Valve’s email:
- Names
- Addresses
- Phone numbers
- Email addresses
- Type and price of the ordered Steam hardware
CEVA retains that shipping information for up to 90 days after an order, so Valve is notifying everyone it can assume was in the retained set — not only people whose parcel was physically in a warehouse on August 1.
What Valve says was not exposed via CEVA: Steam account passwords, payment information, Steam Guard codes, or other Steam account data. You do not need to change your Steam password because of this incident, Valve wrote.
Timeline
- July 29 – August 1, 2026 — Valve: attackers had access to CEVA servers used for Steam hardware shipping data.
- ~August 1 — CEVA confirms to affected customers that a cyber intrusion is impacting European contract logistics; Ace & Tate had cited August 1 access to packing/shipping systems in earlier coverage.
- August 5–8 — Bol, De Bijenkorf, Ajax, ING and Ace & Tate public warnings; dark-web sale reports for some Dutch retail rows.
- August 7 — Valve learns Steam customer delivery data was likely compromised.
- August 10 — Valve customer emails; TechCrunch publishes CEVA’s confirmation and the Dutch DPA’s “10 organisations” figure.
Who is at risk
European Steam hardware buyers whose orders flowed through CEVA in the retention window — Deck owners, Index buyers, accessory shoppers, gift recipients at the shipped address.
Household members who answer the door or the SMS even if they did not place the order.
Not automatically every Steam account. Digital-only players who never ordered hardware through the European CEVA path are outside Valve’s notice. Copycat phishing will still try to scare them.
Staff at other CEVA clients still reviewing scope — Valve’s clear field list is a template for what fulfilment extracts look like.
Phishing you should expect
Valve’s own warning is blunt: attackers may quote your address back to you. Themes already circulating in every CEVA-linked brand story apply here with Steam dressing:
- “Steam Deck held at customs — pay €2.99”
- “Valve Support: verify your hardware order”
- “CEVA / DHL redelivery — click to schedule”
- Voice calls that open with your street address and a recent Deck purchase
None of those should be handled from the message. Open Steam or the Valve/Steam hardware order page yourself. Do not “verify” by typing a Steam Guard code into a link from SMS.
What this is not
This is not a Steam platform account dump. It is not evidence that marketplace wallets or game libraries were pulled from Valve’s own auth systems. It is a third-party shipper breach — the same shape as the Dutch retail notices, now with the world’s largest PC game store’s hardware channel in the blast radius.
It is also not a reason to ignore the notice. Address plus email plus “owns expensive gaming hardware” is enough for porch-pirate casing and convincing delivery fraud.
How CEVA framed the incident
CEVA’s TechCrunch statement emphasises containment to eight European warehouses, an ongoing investigation, and continuity elsewhere. Spokesperson Ryan Fisher would not answer TechCrunch’s questions about how much personal data was taken or whether ransom communications arrived.
For catalog purposes, that statement is enough to mark the CEVA hub row company-confirmed. Client brands remain the clearest public source for field-level detail until CEVA publishes a fuller notice.
Industry context
Shared 3PLs concentrate doorstep identity. One warehouse intrusion becomes a multi-logo notification week. Valve joining Bol and Ajax is not a separate mystery campaign — it is the same European contract-logistics failure mode with a different brand on the email subject line.
Gamers already endure account-takeover phishing year-round. Mixing real shipping fields into that noise raises the hit rate. Security teams at hardware brands should assume shipper retention windows define blast radius as much as SKU volume does.
Related BreachHistory records: Valve / Steam hardware, CEVA hub, Bol, Ajax, Ace & Tate, ING NL.
What you should do
- Read Valve’s email if you received one; keep it for reference.
- Do not change your Steam password solely because of this CEVA incident (per Valve) — unless you reuse that password elsewhere or see separate account oddities.
- Ignore delivery/customs urgency by SMS, email or phone, even when the address matches.
- Check order status only in Steam or the official hardware order flow you already use.
- Watch porch and courier fraud if a Deck or headset is in transit.
- Brief household members who might answer “Steam delivery” calls.
- Employees at Valve/CEVA partners: verify any “CEVA access reset” IT prompts out of band.
Was I affected?
Valve is notifying customers it assumes were impacted based on CEVA’s retention of delivery data. If you ordered Steam hardware shipped in Europe within roughly the prior 90 days and you get the mail, assume the listed fields may be in play. If you get no mail and only buy digital games, you are likely outside this extract — stay sceptical of scare posts claiming “all Steam users.”
No public headcount for Valve’s cohort has been published. BreachHistory keeps recordsAffected at 0 on the Valve row until an attested figure appears.
Regulators
Valve said it is notifying data protection authorities in affected countries. The Dutch DPA’s “10 organisations” comment shows how quickly a single 3PL incident fans into parallel filings. Expect more brand notices before a single EU-wide census.
Canonical record and sources
Valve / Steam hardware CEVA 2026 on BreachHistory · CEVA Logistics hub
Sources: BleepingComputer, TechCrunch, Help Net Security.
Published 2026-08-10.
Steam Guard and account hygiene (still worth doing)
Valve said you need not change your Steam password for this shipper breach. That does not retire normal Steam hygiene. If you have been postponing a Steam Guard app upgrade, recycling an old email password into Steam, or ignoring a login from a country you do not visit, handle those separately. Do not let a “no password change required” line become an excuse to ignore unrelated account warnings.
Phishers will deliberately blur the lines. A message that starts with your real street address and ends with a Steam login link is still a Steam login phish. The address is bait; the login is the steal.
For creators and cafés that ordered hardware in bulk
Studios, cafés and influencers who shipped multiple Decks to one address should assume that address is now a higher-value social-engineering target. Courier impersonation against a business receiving dock may look like a loading-bay delay rather than a consumer SMS. Route all CEVA/Steam shipping questions through purchasing contacts you already trust.
Comparing Valve’s notice to Dutch retail notices
Valve’s email is unusually specific on the access window (July 29–August 1) and on the 90-day retention logic. That helps customers more than a vague “recent orders may be affected” line. Bol’s earlier inventory of fields matches Valve’s shape: contact and order metadata without payment credentials.
The strategic lesson for boards is identical across logos. If a shipper can print your label, a shipper breach can print your customers’ homes. Contract language about encryption, retention days and hour-scale notification is no longer boilerplate.
What remains unknown
CEVA has not published a public field-by-field dump inventory or a victim census. Whether ransom notes were sent is unanswered in the TechCrunch interview. How many of the Dutch DPA’s 10 reporting organisations overlap with brands already in the press is unclear. Those gaps do not block individual action — Valve’s notice is enough to start.
Physical security meets digital fandom
Steam hardware buyers are a visible cohort. Decks travel through airports and LAN parties; unboxing videos announce purchases. Pair that culture with a leaked home address and you get a targeting list that is more personal than a random e-commerce dump. Valve’s phishing warning is not generic compliance language — it matches how this community already talks about packages in public.
Parents who ordered Decks as gifts should tell kids not to answer “Steam warehouse” calls. The child who knows a Deck is coming is exactly who scammers want on the phone.
Freight, ransomware and doorstep data
Logistics cyber risk used to mean delayed containers. It now means delayed containers plus a CRM-shaped extract of every recipient. CEVA’s eight-warehouse footprint is operationally “limited” and still large enough to touch banks’ gift shops, football merch, eyewear and Valve in one news cycle.
Defenders in freight should treat PII retention the way they treat dangerous goods: minimum necessary, shortest shelf life, audited deletion. Ninety days may be commercially convenient; it is also ninety days of blast radius after containment.
How to read Valve’s “no password change” line
Players hear “do not change your Steam password” and sometimes stop reading. The full point is narrower: this particular shipper did not hold Steam credentials, so rotating Steam solely because of CEVA does not remediate a credential that was never taken here. Separately, if Steam emails you about a new login, or you reused the Steam password on a breached site last year, those are different tickets.
Scammers will weaponize the reassurance. Expect messages that say “Valve said you don’t need to change your password — just confirm shipping here.” That is still phishing.
Europe-only shipping path, global phishing audience
Valve’s notice targets European Steam hardware logistics. Social media does not respect that border. Screenshots of the email will circulate in US and Asia Discords within hours, and impostors will mass-mail English speakers who never ordered through CEVA. The defence is the same: if you did not get a message from Valve about your own order, do not invent fear from someone else’s screenshot.
If you are outside Europe but used a freight forwarder or EU address for a Deck purchase, read Valve’s criteria carefully. Forwarding addresses can put you in a European shipper’s file even when you live elsewhere.
What support staff should say on day one
Community mods, café owners and indie studios will field questions before Valve’s FAQ pages catch every edge case. A clean script: CEVA shipper breach; shipping fields possibly exposed; Steam login secrets not held by CEVA; no customs fees by SMS; check your own email for Valve’s notice; report fakes to Steam Support through the client, not through links in the fake.
Do not collect Steam Guard codes “to check if you’re affected.” That is how helpful people become accidental phishing infrastructure.
Dark-web retail rows and Steam hardware rows
Earlier coverage of the Dutch retail side of this wave already described Bol and De Bijenkorf customer data offered for sale. Whether Steam hardware rows appear in the same forums is a separate forensic question. For individuals, assume criminals who buy one brand’s extract can still craft Steam-themed lures using publicly known purchase patterns. The absence of a “Steam” label on a dump does not make address-based delivery fraud harmless.
Board takeaway for hardware brands
If your growth plan depends on physical devices, your privacy plan depends on every 3PL that can print a label. Ask vendors for retention clocks measured in days, not quarters; for breach notification in hours; and for evidence that warehouse OT networks cannot reach the shipping PII store without MFA and just-in-time access. Valve’s clarity is a customer-service win. The underlying concentration risk remains an industry problem.
A short checklist before you close the email
Confirm the sender domain matches Valve’s usual notification pattern as shown in reputable coverage screenshots. Do not trust lookalike domains. If you are waiting on a Deck, track it only inside Steam. If someone at the door asks you to “confirm the breach fee,” that is not how parcel delivery works. If a relative forwards you a panic screenshot from a US Discord claiming every Steam wallet is drained, send them this page and Valve’s own wording instead of amplifying the rumor.
The Valve Steam hardware data breach via CEVA is a logistics story with gaming-brand gravity. Treat the shipping fields as hot. Leave your Steam credentials alone unless something else gives you a reason not to.