“Expect fake messages”: A load of Steam user personal info has been stolen thanks to a cyberattack on one of Valve’s partners, claims report
Steam publisher Valve has warned European customers that a cyberattack on CEVA Logistics, the company that ships Steam hardware across Europe, may have exposed their personal information. The breach affects anyone who bought Steam hardware in the region over the past three months, and Valve is urging affected users to be alert for scam messages that could exploit the leaked details, though it stresses passwords and payment data were not accessed.
According to a Valve email shared online, CEVA was hit between 29 July and 1 August 2026, with Valve learning of the likely compromise on 7 August. The stolen data includes names, phone numbers, emails and postal addresses, which CEVA retains for up to 90 days after an order; credit card details, passwords and Steam Guard codes were not accessible. Valve has warned customers to expect fake emails, texts or calls impersonating Steam, Valve or delivery firms, and says it is pressing CEVA for further details while notifying data protection authorities in the affected countries.
- CEVA Logistics, Valve's European shipping partner, suffered a cyberattack
- Names, phone numbers, emails and addresses of Steam hardware buyers exposed
- Valve warns of likely phishing scams; passwords and payment data are safe