Valve warns that a data breach at its European shipping partner CEVA Logistics may have exposed customer names, addresses, phone numbers, and email addresses for orders of Steam hardware, urging users to beware of phishing messages.
<figure>
<img alt="" data-caption="" data-portal-copyright="Photo: Amelia Holowaty Krales / The Verge" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/268581_Steam_Machine_AKrales_0372.jpg?quality=90&strip=all&crop=0,0,100,100" />
<figcaption>
</figcaption>
</figure>
<p class="wp-block-paragraph">Valve says a data breach may have exposed the personal information of customers who ordered its Steam hardware in Europe. In an email sent to users, Valve says its European shipping partner, CEVA Logistics, suffered a data breach that may have included customer names, addresses, phone numbers, and email addresses.</p>
<p class="wp-block-paragraph">The breach at CEVA occurred between July 29th and August 1st, weeks after Valve began <a href="https://www.theverge.com/games/952191/valve-steam-machine-reservation-preorder-process">taking reservations for its new Steam Machine</a> and <a href="https://www.theverge.com/games/918610/valve-steam-controller-review">Steam Controller</a>. Valve adds that European customer data "was likely compromised" as part of the breach, as CEVA stores "delivery-related information" for up to 90 days after orders.</p>
<div class="image-slider">
<div class="image-slider">
<img src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/steam-hardware-notification_abda01.png?quality=90&strip=all&crop=0,13.322717622081,100,73.354564755839" alt="" title="" data-has-syndication-rights="1" data-caption="" data-portal-copyright="Image: The Verge">
<img src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/steam-hardware-notification-2.png?quality=90&strip=all&crop=0,9.3073593073593,100,81.385281385281" alt="" title="" data-has-syndication-rights="1" data-caption="" data-portal-copyright="Image: The Verge">
<img src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/steam-hardware-notification-3.png?quality=90&strip=all&crop=6.2277580071174,0,87.544483985765,100" alt="" title="" data-has-syndication-rights="1" data-caption="" data-portal-copyright="Image: The Verge">
</div> …</div>
<p><a href="https://www.theverge.com/games/977314/valve-steam-hardware-shipping-data-breach">Read the full story at The Verge.</a></p>
# Steam hardware shipper breach leaks customer data, including names and addresses
Source: [https://www.theverge.com/games/977314/valve-steam-hardware-shipping-data-breach](https://www.theverge.com/games/977314/valve-steam-hardware-shipping-data-breach)
[](https://www.theverge.com/authors/emma-roth)
Emma Roth
is a news writer who covers the streaming wars, consumer tech, crypto, social media, and much more\. Previously, she was a writer and editor at MUO\.
Valve says a data breach may have exposed the personal information of customers who ordered its Steam hardware in Europe\. In an email sent to users, Valve says its European shipping partner, CEVA Logistics, suffered a data breach that may have included customer names, addresses, phone numbers, and email addresses\.
The breach at CEVA occurred between July 29th and August 1st, weeks after Valve began[taking reservations for its new Steam Machine](https://www.theverge.com/games/952191/valve-steam-machine-reservation-preorder-process)and[Steam Controller](https://www.theverge.com/games/918610/valve-steam-controller-review)\. Valve adds that European customer data “was likely compromised” as part of the breach, as CEVA stores “delivery\-related information” for up to 90 days after orders\.
As a result of the breach, Valve says to “expect fake messages” over email, text, or on the phone that claim to come from Steam, Valve, or a delivery company\. “They may quote your address back to you to prove they’re genuine\. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to ‘verify’ your order,” Valve says\. “Treat all of them as fake\.”
The notice says additional data linked to users’ Steam accounts or purchases wasn’t impacted, adding that CEVA “does not have access to your payment information, passwords, Steam Guard codes or other information\.” Valve notes that it only deals with account issues from help\.steampowered\.com, and won’t contact users over email, Steam chat, or Discord\.
**Follow topics and authors**from this story to see more like this in your personalized homepage feed and to receive email updates\.
- Emma Roth
Dozens of malicious wallpapers on Steam Workshop have been found to contain malware that steals accounts, installs backdoors, or crypto miners, primarily targeting Chinese and Russian gamers.
Trezor disclosed a data breach at shipping provider ShipMonk exposing personal data of ~13,700 customers, though Trezor systems and private keys were not compromised. CZ (Binance) comments on the differing risk profiles between hardware and software wallets.
A massive supply-chain attack on the open-source AI tool LiteLLM exposed terabytes of credentials from thousands of organizations, including Microsoft, Amazon, and Cisco, during a 40-minute window in March. Security firms CloudSEK and Hudson Rock disclosed the breach, attributing it to the TeamPCP gang.
LastPass is notifying users of a data breach caused by a compromise at its third-party vendor Klue, exposing customer names, email addresses, and support case data, but not password vaults.
Valve is discontinuing its physical Steam gift card program due to widespread scammers, ending its last link to brick-and-mortar retail despite the significant revenue from physical cards.