Aug 12, 2026 · 7 min read
Valve Warns Steam Buyers After CEVA Logistics Hack
Valve never lost a single Steam password. It lost something arguably more useful to a scammer: a verified account email address sitting next to a real name, a street address, a phone number, and the exact model and price of the hardware you just bought.
On August 10, 2026, Valve emailed European customers who had ordered a Steam Deck, a Steam Machine or a Steam Controller to tell them their delivery data was stolen. The intrusion was not at Valve. It happened at CEVA Logistics, the contract logistics operator that ships Steam hardware across Europe, and the same breach simultaneously handed attackers customer lists belonging to a Dutch bank, a football club, an eyewear brand and one of the largest ecommerce sites in the Netherlands.
Key Takeaways
- The CEVA Logistics intrusion ran from July 29 to August 1, 2026; Valve was told its customer data had been taken on August 7 and notified affected buyers on August 10, per BleepingComputer's report.
- Exposed fields include full name, street address, postal code, city, country, phone number, the email address linked to the Steam account, and the type and price of the hardware ordered.
- Steam passwords, Steam Guard codes and payment data were not exposed, because CEVA never held them.
- CEVA's contract logistics division saw eight European warehouses disrupted, with Bol, De Bijenkorf, ING, Ajax and Ace & Tate among the confirmed downstream victims and at least ten organisations filing with the Dutch data protection authority.
- Valve told customers to expect phishing by email, SMS and voice, and to treat all such messages as fake.
What Happened at CEVA Logistics?
Attackers were inside CEVA Logistics systems for roughly four days at the end of July 2026, and CEVA began telling its retail clients on August 1. CEVA is not a small vendor: it is a wholly owned subsidiary of CMA CGM, it runs about 1,000 warehouses, and it moved 15 million shipments in 2025 on $18.3 billion of revenue.
CEVA says the operational impact was confined to eight warehouses in its contract logistics arm, that no other systems globally were affected, and that the affected systems were isolated, taken offline and handed to outside investigators. What CEVA has not said is how the attackers got in, how much data left, or how many people are affected. The Register reported that CEVA did not respond to questions, and TechCrunch noted the company declined to say whether it had heard from the attackers at all.
No attribution has been publicly confirmed. Claims naming a ransomware as a service crew have circulated on aggregator sites, but no established outlet has verified a leak site posting. Treat attribution as open.
What Data Was Exposed in the Steam Hardware Breach?
Everything a courier needs to put a box in your hands, plus the contents of that box. Per Valve's notification, summarised by Help Net Security, the exposed set covers:
- Full name
- Street address, postal code, city and country
- Phone number
- The email address attached to your Steam account
- The type of hardware ordered and the price paid
Valve was clear about the boundary: "Additional information related to your Steam account or other purchases was not impacted." Passwords, Steam Guard codes and payment details never sat in CEVA's systems. CEVA held delivery data for up to 90 days after an order, which is why only buyers from a narrow window are being notified.
Bol and De Bijenkorf confirmed an almost identical field list. That is what a shared fulfilment vendor breach looks like: one intrusion, five customer databases with the same schema.
Why Does "No Passwords Leaked" Understate the Risk?
Because the value of this data set is not access, it is credibility. A credential dump gives an attacker a login attempt. An order record gives an attacker a script.
A message can now address you by your real name, quote the street you live on, name the exact device you bought, state the price you paid, and arrive at the email address Valve genuinely uses. The generic phishing tells that awareness training drills into people, wrong name, wrong product, unfamiliar address, are all absent.
Two attack shapes follow. First, the customs or redelivery fee lure: a small payment request tied to a shipment the victim knows is real. Valve warned explicitly that scammers may quote the customer's address and demand payment for customs charges or account verification. Second, package redirection, where the caller has enough order detail to talk a courier's support line into changing the delivery address on a device worth several hundred euros.
Steam accounts are a durable target on their own. Silent Push documented browser in the browser phishing kits aimed at Steam players, rendering a fake Steam login window inside the page with a spoofed URL bar and live relay of two factor codes. Those kits already worked. What changed on August 10 is that operators now hold confirmed Steam account emails for people who just spent money on Valve hardware. Not a cold list.
Why Can't You Opt Out of Your Retailer's Shipping Partner?
You cannot, and that is the structural point here. Valve's own security posture was irrelevant. You chose to buy from Valve; nobody offered you a choice about CEVA, and the checkout page never named it.
This is the same pattern as the Amgen breach that exposed patient data held in third party clouds, and it rhymes with the Levi Strauss breach that needed no exploit at all. The weak link keeps sitting one contract away from the brand you actually trusted.
For defenders the lesson is blunt. A fulfilment vendor holding 90 days of name, address, phone, email and line item data across dozens of retail clients is a higher value target than most of those clients individually, and it is unlikely to be defended to the standard of the largest name on its books.
What This Means for Your Inbox
The stolen field that will do the most damage is the email address: verified, tied to a named individual at a known street address, and confirmed as the address a specific company legitimately mails. Breach dumps keep resurfacing as phishing waves months later, exactly the cycle we saw with the Alcon leak of 218,000 business email addresses.
Filtering will not save you here. A message carrying your correct name, address and order details has none of the statistical noise a spam classifier keys on, and the pattern behind fake cloud storage payment emails transfers directly: a small, plausible charge attached to a service you genuinely use. Verification has to move out of the message and into the platform.
What Should Affected Steam Customers Do Now?
Assume every Steam or courier message you receive for the next several months is hostile until proven otherwise, and verify inside the client rather than through the message.
- Never click a link in a Steam themed email. Open the Steam client or type the address yourself. Order and support status lives in your account, not in your inbox.
- Pay nothing on demand. Valve does not chase you by email for customs fees on a completed order. A payment request tied to a shipment is the single strongest signal of fraud in this scenario.
- Confirm Steam Guard is on the right device and review authorised devices in Steam's account security settings. Steam Guard was not breached, which makes it exactly the control worth checking.
- Treat phone calls the same way. Valve warned about voice phishing explicitly, and the attackers have your number alongside your order. If a courier calls about redirecting or rescheduling a shipment, hang up and verify through the retailer.
- Check your address against known dumps at Have I Been Pwned and turn on notifications so future appearances reach you before the phishing does.
Valve handled the notification well: fast disclosure, an exact breach window, a precise field list, and a direct warning about the phishing to come. That is more transparency than CEVA itself has offered. But no notification changes the arithmetic. One logistics vendor's bad week produced a target list where the attacker knows your name, where you live, what you bought and where to email you. The passwords stayed safe. The pretext did not.
The pattern repeated three months later at a different fulfilment provider: a breach at ShipMonk exposed 13,689 Trezor hardware wallet customers, again with names, phone numbers and home addresses attached to a known purchase.