PSA: Steam users have been hit by a cyber attack, ‘expect fake messages’
Valve has warned Steam Machine and Steam Controller users in Europe that a cyber attack on its logistics partner CEVA Logistics has exposed their personal data. CEVA, which handles hardware fulfilment for Valve in Europe, notified the company of the breach on 7 August 2026, prompting Valve to alert affected customers and urge vigilance against follow-up scam attempts.
Valve says payment details and passwords were not compromised, but leaked data may include names, addresses, country of residence, phone numbers, associated email accounts and hardware purchase information. It is warning users to expect fake emails, texts or calls posing as Steam, Valve or a delivery firm, which may cite real order details to appear convincing and ask for payment or login "verification". Valve stressed that genuine Steam Support only operates via help.steampowered.com and will never request a password or Steam Guard code, and confirmed CEVA has isolated affected systems, taken them offline, brought in outside investigators, and is notifying relevant data protection authorities.
- Valve's logistics partner CEVA was hacked, exposing European customers' personal data.
- Passwords and payment details were not compromised in the breach.
- Valve warns users to expect and ignore fake delivery or verification messages.