Valve, the publisher behind the Steam platform, has begun notifying its European customers after a cyberattack hit CEVA Logistics, its provider responsible for shipping Steam hardware in Europe. The incident, which occurred between July 29 and August 1, 2026, allowed attackers to access the logistics provider's servers and steal delivery information related to Steam hardware orders.

What Valve revealed in its notifications

According to the notification emails sent to affected customers — the first instances of which were reported on social media on August 10 — Valve was informed of the incident by CEVA only on August 7, nearly a week after the attack window ended. In these communications, Valve directly quotes CEVA:

“Between July 29, 2026, and August 1, 2026, a cyberattack hit CEVA Logistics, the company that ships Steam hardware to customers in Europe. CEVA is still investigating this attack, but as Valve learned on August 7, certain information about Steam customers, including you, was likely compromised.”

The publisher clarifies that CEVA receives only the strictly necessary information from Steam for the shipping of physical hardware: name, postal address, phone number, email address, as well as the type and price of ordered products. It is precisely this data that has been compromised.

A crucial point: no Steam passwords, payment information, or Steam Guard codes have been exposed, as CEVA does not have access to this information in its logistical functions. The compromised data only concerns delivery-related information.

A 90-day exposure window

One factor considerably exacerbates the scope of the incident: CEVA Logistics retains delivery data for up to 90 days after purchase. Valve, therefore, sent its notification to all customers who ordered physical hardware in the past three months. Any European buyer of Steam hardware during this period should consider themselves potentially affected.

This 90-day retention, while operationally understandable for a logistics provider, significantly expands the number of people exposed compared to a leak limited to only the orders in progress at the time of the attack.

CEVA Logistics: a transportation giant already targeted

CEVA Logistics is not a minor player. According to BleepingComputer, the company is a 100% subsidiary of the CMA CGM Group, the third largest container shipping company in the world. CEVA operates 1,000 warehouses, processed 15 million shipments last year, and reported a revenue of $18.3 billion in 2025.

Furthermore, the Steam incident is not isolated within CEVA's cyber history. As ZATAZ points out, the domain cevalogistics.com had already been linked to a cyberattack in 2025: the Coin Base Cartel group had then offered for sale a database that it claimed was stolen from the company. While there is no evidence to establish a direct link between this previous claim and the current incident, this prior issue indicates that CEVA was already on the radar of cybercriminals.

Additionally, BleepingComputer reports an important fact: as early as August 1, CEVA Logistics informed several European retailers that a cyberattack had disrupted operations in eight of its European warehouses. The incident affecting Steam customers is therefore part of a broader event impacting CEVA's logistical infrastructure in Europe.

The main danger: ultra-targeted phishing

While the absence of compromised passwords or payment data may provide reassurance, the residual risk is far from negligible. The stolen data — name, address, phone, email, and order details — are exactly the types that enable the design of highly credible phishing campaigns.

A fraudulent message mentioning a real order, citing the recipient's actual address and the exact contents of their purchase, will appear immediately legitimate. Valve itself warns its customers in its notification:

“They may quote your address back to you to prove they're genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to 'verify' your order. Treat all of them as fake.”

The most likely attack scenarios identified by ZATAZ and Valve include:

  • Fake customs fees or additional delivery charges
  • Pretended redelivery of a blocked package
  • Urgent password reset requests via a link leading to a page imitating Steam
  • Phone calls impersonating Steam, Valve, CEVA, or other carriers

The latter scenario presents a particularly high risk: a fake link can lead to a counterfeit authentication page mimicking Steam. By entering their credentials there, the user directly transmits them to the attackers.

Steam accounts, a currency on the dark web

Analysis by the ZATAZ Watch Service, conducted across 27 black markets selling different types of customer accounts, reveals that stolen Steam accounts are offered at around 9 euros on average. This market gives direct value to credentials obtained after a successful phishing campaign, making the exploitation of CEVA's data economically attractive for cybercriminals.

A context that amplifies the impact

The leak occurs amidst the launch of the Steam Machine, Valve's physical hardware. Customers who have sometimes waited months for their equipment now discover an additional consequence of their purchase. The combination of a high volume of orders and a 90-day data retention period explains why the number of potentially exposed customers could be significant.

A recent precedent at Steam

As ZATAZ reminds us, Steam had previously been affected in May 2025 by a massive leak impacting nearly 89 million accounts, at that time through a different third party. This episode illustrates a structural point: the exposure of a large digital service does not solely depend on its own infrastructure. Its subcontractors, logistics providers, and partners can also become points of entry or leaks — sometimes even more easily than the primary service itself.

Measures taken and to come

Valve indicates it is actively cooperating with CEVA to determine precisely the extent of the data theft. The publisher claims to have initiated the necessary actions with data protection regulators in the affected countries, in accordance with its regulatory obligations (GDPR especially for customers in the European Union).

For its part, CEVA Logistics has isolated the affected systems, taken all related infrastructure offline, and has engaged external investigators to analyze the incident.

Practical advice for affected customers

For individuals who ordered physical hardware from Valve in the past three months, the following precautions are advisable:

  1. Beware of any unexpected communication — whether from an email, SMS, or call — mentioning a Steam order, delivery, or account issue.
  2. Never enter your Steam credentials on a link received via message. Steam Support never asks for a password or a Steam Guard code.
  3. Consider urgency as a warning signal: a message seeking to provoke immediate reaction is often part of a manipulation mechanism.
  4. Independently verify any requests by going directly to the official Steam site, without clicking on links provided in the messages.
  5. It is not necessary to change your Steam password following this incident, according to Valve, since passwords have not been compromised.

The issue for the coming weeks, from a cyber intelligence perspective, will be to monitor the possible emergence of phishing campaigns specifically exploiting the data stolen from CEVA to turn a logistical leak into large-scale Steam account compromises.