Valve is alerting Steam Machine purchasers that scammers may have access to their addresses.
Valve has sent emails to European customers who purchased a Steam Machine or Steam Controller. A cyberattack on CEVA Logistics, the company responsible for shipping Valve hardware in Europe, compromised delivery information. CNET’s Tyler Graham reported on this alert on Monday. CEVA informed Valve about the breach on August 7, and Valve spent the next few days determining who to notify.
A spokesperson from Valve told CNET that CEVA is still investigating the incident. The company opted to contact everyone it reasonably believed might be impacted, based on the current information it has.
Valve produces hardware in addition to operating its store. The Steam Machine and Steam Controller follow the Steam Deck, with all of these products being shipped to Europe through a logistics contractor.
What was exposed and what was not
The compromised data includes names, countries, street addresses, phone numbers, and email addresses. BleepingComputer also noted that the product type and purchase price were included in the breach.
One line in the notification stands out. The email address linked to the order matches the one used for the Steam account, giving scammers access to the specific inbox of concern.
However, payment information, passwords, and Steam Guard codes were not part of the breach. Valve has stated that CEVA never had access to this sensitive information.
Additionally, Valve mentioned that shipment information remained with CEVA for 90 days after each order, which defines the scope of those affected.
The importance of the warning
Valve’s email advises customers to be on the lookout for fraudulent messages regarding their orders, and recipients have shared the notification on Reddit. These messages may come via email, text, or phone and could seem to originate from Steam, Valve, or a courier service.
Importantly, the messages may reference the customer’s own address to seem legitimate and could request a minor customs or redelivery fee.
“Consider them all to be scams,” the email states.
Valve also notes that Steam support addresses issues only through its official help page and never through email, Steam chat, or Discord. Its representatives will never ask for a password or a Steam Guard code, nor will a courier.
No action is required for accounts. There’s no need for anyone to change their Steam password or modify settings, as the breach did not compromise those areas.
Eight warehouses and a growing list
TechCrunch’s Zack Whittaker traced the cyberattack back to July 29. According to Valve’s notice, the infiltration occurred between that date and August 1, with CEVA confirming it on the same day, six days prior to notifying Valve.
Valve is just one among several names on a longer list. Whittaker identified Dutch retailers Bol and De Bijenkorf, the bank ING, eyewear company Ace & Tate, and football club Ajax as also being affected.
The logistics side has suffered its own issues. FreightWaves reported that eight European warehouses experienced disruptions, resulting in delays for orders, returns, and refunds.
Bol and De Bijenkorf have suspended data exchanges with CEVA as a precaution, as reported by Eric Kulisch. Products at the impacted locations have been taken offline.
The supplier's prominence
CEVA is a significant vendor, operating over 1,000 warehouses, handling approximately 15 million shipments annually, and reporting $18.3 billion in revenue in 2025 as a subsidiary of the CMA CGM shipping group.
This scale underlines a crucial issue. A single breach at a logistics contractor can impact a gaming company, a bank, and a football club within a brief period, highlighting what people refer to as a digital supply chain.
This pattern is not new. LastPass customers lost data via a supplier breach rather than through LastPass itself. Similarly, Polymarket users lost funds in a comparable third-party breach.
What remains unknown
The exact number of affected customers is unclear. Neither Valve nor CEVA has disclosed how much data was compromised or how the attackers gained access.
Attribution is still lacking as no group has claimed responsibility for the breach, and no published information identifies one.
CEVA has offered limited comments, stating to TechCrunch that the incident impacted part of its European contract logistics operations, while other operations are running smoothly.
Valve has shared a bit more information, indicating that CEVA has isolated the compromised systems, taken them offline, and engaged external investigators, and that Valve continues to press the contractor for a complete understanding of the incident's extent.
Regulatory action is forthcoming. Valve is informing the data protection authority in each affected country and has designated Artana Digital GmbH in Hamburg as the point of contact for inquiries regarding the incident.
The Dutch regulator is already looking into the matter, with Dutch police having shut down 800 servers in a separate operation earlier this year.
For now, further developments are awaited. Individuals who ordered a Steam Machine now have their home addresses stored in someone else's database, and the only defense Valve can offer is the advice to disregard the next seemingly legitimate message about their order.
Other articles
Valve is alerting Steam Machine purchasers that scammers may have access to their addresses.
A cyberattack targeting the logistics company CEVA revealed the names, addresses, and phone numbers of purchasers of European Steam Machines and Controllers.
