Tech

Valve warns of data breach affecting European Steam hardware customers

The gaming giant confirms that while payment and account credentials remain secure, customers should treat all unsolicited communications as fraudulent following the July and August incident.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: The Verge · original
Steam hardware shipper breach leaks customer data, including names and addresses
Shipping partner CEVA Logistics incident exposes personal details of device buyers

Valve has issued a security alert to customers in Europe regarding a data breach involving its European shipping partner, CEVA Logistics. The incident, which occurred between 29 July and 1 August 2026, may have exposed personal information of individuals who ordered Steam hardware, including names, addresses, phone numbers, and email addresses. Valve clarified that the breach is limited to delivery-related information stored by the logistics provider for up to 90 days after orders.

The company confirmed that payment information, account passwords, and Steam Guard codes remain secure, as CEVA Logistics does not have access to such data. This distinction is critical for investors and consumers alike, as the compromise is restricted to logistical metadata rather than core financial or authentication credentials. The breach took place weeks after Valve began taking reservations for its new Steam Machine and Steam Controller, highlighting the risks associated with hardware distribution channels.

Valve advises customers to treat any unsolicited communications claiming to be from Steam, Valve, or delivery services as fraudulent. The company noted that malicious actors may quote addresses back to victims to appear genuine and could request payment for customs or redelivery fees. Recipients are urged to disregard these messages entirely, particularly those sent via email, text, or phone.

To mitigate further risk, Valve specified that it only deals with account issues via help.steampowered.com. The company explicitly stated it will not contact users over email, Steam chat, or Discord regarding account matters. This guidance aims to prevent social engineering attacks that rely on the recently exposed personal data to trick users into revealing further information or making payments.

The exact volume of affected customers has not been specified in the provided source material. However, the incident underscores the importance of supply chain security in the technology sector. As Valve continues to expand its hardware offerings, the reliance on third-party logistics providers introduces potential vulnerabilities that extend beyond the core platform itself.

Continue reading

More from Tech

Read next: France Enacts Strict Ban on Unsolicited Telemarketing Calls
Read next: OpenAI expands Daybreak cybersecurity programme with new model tiers
Read next: AI models map 766 genes in schizophrenia genetic architecture