Valve is cautioning buyers of Steam Machines that scammers may have access to their address.
Valve has reached out via email to European customers who purchased a Steam Machine or a Steam Controller. This was due to a cyberattack on CEVA Logistics, the company responsible for shipping Valve hardware throughout Europe, which compromised their delivery information. CNET’s Tyler Graham reported this alert on Monday. CEVA informed Valve about the incident on August 7, and Valve spent the subsequent days determining who to notify.
A spokesperson for Valve mentioned to CNET that CEVA is still looking into the matter. The company chose to inform everyone it could reasonably believe was impacted based on its current knowledge. Valve is involved in hardware production as well as operating the store. The Steam Machine and Steam Controller follow the Steam Deck, all of which are transported into Europe through a logistics contractor.
What was exposed and what wasn't
The compromised information includes names, countries, street addresses, phone numbers, and email addresses. According to BleepingComputer, the product type and the amount paid were also included in this data.
One phrase in the notice carries significant weight. The email address on the order matches the one associated with the Steam account, meaning that a scammer now has access to the specific inbox of concern. However, payment details, passwords, and Steam Guard codes were not compromised, as Valve stated that CEVA never had access to them. Valve also noted that shipping information was held by CEVA for 90 days post-order, determining who was potentially affected.
The warning is the important part
Valve’s email warns customers to be on the lookout for fraudulent communications regarding their orders, and recipients have shared this information on Reddit. Such messages may arrive through email, text, or phone and could seem to be from Steam, Valve, or a courier.
The email emphasizes an important point: these messages may reference the customer's own address to appear legitimate and may request a small customs or redelivery fee. "Treat all of them as fake," the email advises. Valve adds that Steam support only addresses issues via its official help page and never via email, Steam chat, or Discord. Its staff will never request a password or a Steam Guard code, and neither will a courier.
Customers do not need to take action regarding their accounts. There is no need to change a Steam password or modify settings, as the breach did not affect either.
Eight warehouses and a growing list
TechCrunch’s Zack Whittaker tracked the attack back to July 29. Valve's notice states the breach occurred between that date and August 1, with CEVA confirming it that same day, six days before notifying Valve.
Valve is just one name on a longer list. Whittaker has mentioned Dutch retailers Bol and De Bijenkorf, the bank ING, the eyewear company Ace & Tate, and the football club Ajax. The logistics aspect has been impacted as well. FreightWaves reported disruptions at eight European warehouses, causing delays in orders, returns, and refunds. Bol and De Bijenkorf halted data exchanges with CEVA as a precaution, according to Eric Kulisch’s reporting, causing products at the affected sites to go offline.
The supplier is significant
CEVA is a substantial vendor, operating over 1,000 warehouses and managing approximately 15 million shipments annually, reporting $18.3 billion in revenue in 2025 as part of the CMA CGM shipping group. This scale is crucial, as one breach at a contract logistics provider can impact a games company, a bank, and a football club all in the same week—illustrating the interconnectedness of the digital supply chain.
The trend is familiar. LastPass users had their data compromised through a third-party vendor, and Polymarket customers lost funds in a similar third-party breach.
What remains unknown
However, the number of affected customers remains unclear. Both Valve and CEVA have not disclosed how many individuals are impacted, the amount of data compromised, or how the attackers infiltrated the system. Attribution is also lacking, as no group has taken responsibility for the breach, and nothing published currently identifies one.
CEVA has provided little information, stating to TechCrunch that the incident affected part of its European contract logistics operations, but other operations continue without issues. Valve has shared a bit more detail, indicating that CEVA has isolated the affected systems, taken them offline, and engaged external investigators, while Valve continues to seek full clarity from the contractor.
Regulators will follow up next. Valve is informing the data protection authority in each affected country and has designated Artana Digital GmbH in Hamburg as the point of contact for inquiries about the incident. The Dutch data protection authority is already investigating, and Dutch police had dismantled 800 servers in an unrelated operation earlier this year.
Everything else is pending. Customers who ordered a Steam Machine now have their home addresses in someone else's possession, and Valve’s only guidance is to be skeptical of any forthcoming messages regarding their package.
Other articles
Valve is cautioning buyers of Steam Machines that scammers may have access to their address.
A cyberattack targeting logistics company CEVA revealed the names, addresses, and phone numbers of purchasers of European Steam Machines and Controllers.
