Technology

Valve Says Some Steam Hardware Buyers' Personal Info Was Exposed in a Shipping Company Breach

Martin HollowayPublished 4d ago4 min readBased on 2 sources
Reading level
Valve Says Some Steam Hardware Buyers' Personal Info Was Exposed in a Shipping Company Breach
Image by tianya1223 from Pixabay

Valve has told European customers who ordered Steam hardware that their personal information may have been exposed in a data breach at its shipping partner, CEVA Logistics. The company said it learned on August 7, 2026 that customer data was likely compromised in the incident, which took place between July 29 and August 1. VideoCardz

The breach may have included customer names, addresses, phone numbers, and email addresses, according to Valve. The exposure happened because CEVA keeps delivery information for up to 90 days after orders are delivered, so the affected data covers a window of recent European hardware shipments. The Verge

Valve has been clear about what was and was not exposed. Payment information, passwords, and Steam Guard codes were not affected, because CEVA does not have access to those systems. Other data linked to users' Steam accounts or purchases was also unaffected. The breach was limited to the shipping company's systems, not Valve's own.

The main concern Valve is raising is phishing — when scammers pretend to be a trusted company to trick you into giving up information or clicking bad links. With names, addresses, phone numbers, and email addresses potentially in the hands of attackers, the combination is a ready-made kit for targeted scams. Valve warned customers to treat as fake any messages over email, text, or phone claiming to come from Steam, Valve, or a delivery company that quote your address or ask you to confirm a delivery, pay customs or redelivery fees, or sign in to verify an order. The specificity of the guidance, naming particular excuses like customs fees and redelivery charges, signals that Valve considers impersonation scams the most likely follow-on threat.

Valve also reminded customers that it only handles account issues through help.steampowered.com and will never contact users over email, Steam chat, or Discord. If a message arrives through any other channel about a hardware order, the default assumption should be that it is fraudulent.

The broader context here is that this is a common pattern in the tech industry. A company like Valve can have strong security on its own systems, but still be exposed when a partner — in this case, a shipping company — holds customer data and gets breached. CEVA had no payment data, no passwords, no login information. The dataset was shipping-only. Yet a name plus a physical address plus a phone number plus an email is exactly what scammers need to make their messages believable. An attacker who knows you ordered hardware and can quote your real delivery address has already passed the trust test that ordinary scam emails never pass.

The 90-day retention window is also worth noting. Valve did not say how many customers fall within that window, nor has CEVA disclosed how many people were affected beyond the dates. But the retention policy itself raises a question worth asking. Ninety days of delivery records is a standard practice that supports returns and customer service. It is also, as this incident shows, a period during which a breach at the shipping company creates a live risk for the platform's customers.

Valve's communication has been direct. The company has not downplayed the incident, has specified what data is at risk, has drawn a clear line around what was not affected, and has given customers practical guidance on what to watch for. That is a reasonable template for how a company should respond when a partner's breach affects its users.

Because no payment or password data was exposed, the scope of this incident is limited. The realistic threat is phishing, and Valve has named it directly. Customers who ordered Steam hardware delivered in Europe within the relevant window should treat any unexpected contact about their order with suspicion, check through help.steampowered.com, and avoid clicking links or providing information through any other channel.