Valve is cautioning buyers of Steam Machines that scammers may have access to their address.

Valve is cautioning buyers of Steam Machines that scammers may have access to their address.

      Valve has reached out via email to European customers who purchased a Steam Machine or a Steam Controller. This was due to a cyberattack on CEVA Logistics, the company responsible for shipping Valve hardware throughout Europe, which compromised their delivery information. CNET’s Tyler Graham reported this alert on Monday. CEVA informed Valve about the incident on August 7, and Valve spent the subsequent days determining who to notify.

      A spokesperson for Valve mentioned to CNET that CEVA is still looking into the matter. The company chose to inform everyone it could reasonably believe was impacted based on its current knowledge. Valve is involved in hardware production as well as operating the store. The Steam Machine and Steam Controller follow the Steam Deck, all of which are transported into Europe through a logistics contractor.

      What was exposed and what wasn't

      The compromised information includes names, countries, street addresses, phone numbers, and email addresses. According to BleepingComputer, the product type and the amount paid were also included in this data.

      One phrase in the notice carries significant weight. The email address on the order matches the one associated with the Steam account, meaning that a scammer now has access to the specific inbox of concern. However, payment details, passwords, and Steam Guard codes were not compromised, as Valve stated that CEVA never had access to them. Valve also noted that shipping information was held by CEVA for 90 days post-order, determining who was potentially affected.

      The warning is the important part

      Valve’s email warns customers to be on the lookout for fraudulent communications regarding their orders, and recipients have shared this information on Reddit. Such messages may arrive through email, text, or phone and could seem to be from Steam, Valve, or a courier.

      The email emphasizes an important point: these messages may reference the customer's own address to appear legitimate and may request a small customs or redelivery fee. "Treat all of them as fake," the email advises. Valve adds that Steam support only addresses issues via its official help page and never via email, Steam chat, or Discord. Its staff will never request a password or a Steam Guard code, and neither will a courier.

      Customers do not need to take action regarding their accounts. There is no need to change a Steam password or modify settings, as the breach did not affect either.

      Eight warehouses and a growing list

      TechCrunch’s Zack Whittaker tracked the attack back to July 29. Valve's notice states the breach occurred between that date and August 1, with CEVA confirming it that same day, six days before notifying Valve.

      Valve is just one name on a longer list. Whittaker has mentioned Dutch retailers Bol and De Bijenkorf, the bank ING, the eyewear company Ace & Tate, and the football club Ajax. The logistics aspect has been impacted as well. FreightWaves reported disruptions at eight European warehouses, causing delays in orders, returns, and refunds. Bol and De Bijenkorf halted data exchanges with CEVA as a precaution, according to Eric Kulisch’s reporting, causing products at the affected sites to go offline.

      The supplier is significant

      CEVA is a substantial vendor, operating over 1,000 warehouses and managing approximately 15 million shipments annually, reporting $18.3 billion in revenue in 2025 as part of the CMA CGM shipping group. This scale is crucial, as one breach at a contract logistics provider can impact a games company, a bank, and a football club all in the same week—illustrating the interconnectedness of the digital supply chain.

      The trend is familiar. LastPass users had their data compromised through a third-party vendor, and Polymarket customers lost funds in a similar third-party breach.

      What remains unknown

      However, the number of affected customers remains unclear. Both Valve and CEVA have not disclosed how many individuals are impacted, the amount of data compromised, or how the attackers infiltrated the system. Attribution is also lacking, as no group has taken responsibility for the breach, and nothing published currently identifies one.

      CEVA has provided little information, stating to TechCrunch that the incident affected part of its European contract logistics operations, but other operations continue without issues. Valve has shared a bit more detail, indicating that CEVA has isolated the affected systems, taken them offline, and engaged external investigators, while Valve continues to seek full clarity from the contractor.

      Regulators will follow up next. Valve is informing the data protection authority in each affected country and has designated Artana Digital GmbH in Hamburg as the point of contact for inquiries about the incident. The Dutch data protection authority is already investigating, and Dutch police had dismantled 800 servers in an unrelated operation earlier this year.

      Everything else is pending. Customers who ordered a Steam Machine now have their home addresses in someone else's possession, and Valve’s only guidance is to be skeptical of any forthcoming messages regarding their package.

Other articles

Valve is alerting Steam Machine purchasers that scammers may have access to their addresses. Valve is alerting Steam Machine purchasers that scammers may have access to their addresses. A cyberattack targeting the logistics company CEVA revealed the names, addresses, and phone numbers of purchasers of European Steam Machines and Controllers. Google Play has introduced Venmo as a payment option in the United States. Additionally, it is experimenting with cash payment methods in other markets. Google Play has introduced Venmo as a payment option in the United States. Additionally, it is experimenting with cash payment methods in other markets. Google Play now allows Venmo for payments on apps, games, subscriptions, and creator tips in the United States. In developing countries, users have the option to pay in cash at a local store. The Arena Group is changing its name to Paradium.AI, and its revenue has recently dropped by fifty percent. The Arena Group is changing its name to Paradium.AI, and its revenue has recently dropped by fifty percent. The Arena Group will change its name to Paradium.AI by the end of August. Revenue for the second quarter decreased to $22.2 million, down from $45.0 million the previous year. Hackers managed to gain access to Levi's, and just three computers sufficed. Hackers managed to gain access to Levi's, and just three computers sufficed. Levi Strauss reports that attackers employed social engineering tactics to access the computers of three employees and steal corporate data. There was no involvement of consumer data. Cybersecurity stocks reached all-time highs, and one analyst's target was only valid for a morning. Cybersecurity stocks reached all-time highs, and one analyst's target was only valid for a morning. CrowdStrike and Palo Alto Networks reached all-time highs as analysts increased their targets regarding AI agent threats. One of the targets was surpassed on the same day. Google is experimenting with a homepage that does not include a Search button. Google is experimenting with a homepage that does not include a Search button. Users who are signed out are encountering three AI shortcuts in place of the Search button. Two of these shortcuts are functional without an account, while one requires an account to work.

Valve is cautioning buyers of Steam Machines that scammers may have access to their address.

A cyberattack targeting logistics company CEVA revealed the names, addresses, and phone numbers of purchasers of European Steam Machines and Controllers.