
Steam Data Breach Hits European Customers After Shipping Partner Hack
.webp)
Valve has started notifying Steam hardware customers across Europe that hackers stole their personal details. The Steam data breach did not begin on Valve's own infrastructure. Attackers instead broke into CEVA Logistics, the shipping company that delivers Steam hardware orders to European buyers.
The intrusion ran from July 29 to August 1, 2026. During that window the attackers reached the information CEVA uses to ship physical orders to Steam customers. CEVA alerted its corporate clients on August 1, but the scale of the data loss took another week to surface.
Valve learned on August 7 that the attackers had likely taken customer information. Notification emails reached affected buyers on August 10. Because the Steam data breach started at a supplier, Valve depends on CEVA for a full account of what left the network and how the attackers got in.
What the Steam Data Breach Exposed
The stolen records cover names, home addresses, phone numbers and email addresses. They also include the type and price of every product ordered. That combination hands an attacker a verified identity, a working contact route and a purchase history in one package.
Valve drew a clear line around what stayed out of reach. CEVA never held payment card details, Steam passwords, Steam Guard codes or any other account credentials. No wider Steam purchase history sat inside the compromised systems either.
Because of that separation, Valve told customers to leave their passwords and account settings alone. The advice cuts against the standard breach playbook, but it fits the facts. The Steam data breach stopped at the delivery layer, and nothing in the exposed dataset opens a route into an account.
A 90-Day Retention Window Defined the Victim List
CEVA keeps delivery information for up to 90 days after an order ships. Valve used that retention period to decide who deserved a warning. Rather than wait for a confirmed list of affected buyers, the company emailed everyone who plausibly fell inside the window.
The Steam data breach notification therefore went to a wider group than the confirmed victim count. That decision favours caution, and it also exposes a structural weakness in vendor relationships. Valve could not name the affected customers precisely, because the records lived in another company's system under another company's retention rules.
CEVA is still investigating. Until that work finishes, the true reach of the Steam data breach stays an open question.
Why the Phishing Warning Came First
Valve spent most of its notification on fraud rather than account security. The reasoning is straightforward. Names paired with verified home addresses, phone numbers and order values make convincing scams far easier to build.
The company warned customers to expect email, SMS and voice scams impersonating Steam, Valve or delivery firms. Attackers can recite a real home address to sound legitimate. They may ask a customer to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to verify an order.
Valve told customers to treat every such message as fake. Anyone caught in the Steam data breach should expect delivery-themed lures over the coming months. Legitimate retailers do not chase surprise fees by text message.
One Compromised Vendor, Many Exposed Brands
The Steam data breach forms one piece of a far larger incident. CEVA Logistics runs more than 1,000 warehouses worldwide, moved roughly 15 million shipments last year and reported $18.3 billion in revenue for 2025. The attack disrupted operations at eight of its European warehouses.
Other brands using those sites have issued their own warnings. Dutch retailer Bol, luxury department store De Bijenkorf, football club Ajax, banking group ING and eyewear brand Ace & Tate all told customers that attackers may have taken their shipping details. Delays and cancelled orders followed at several of them.
One compromised logistics provider therefore reached gamers, bank customers, football fans and shoppers at once. None of those organisations lost control of their own systems. Each of them still carries the notification duty, the regulatory filing and the customer trust problem that follows. Supplier risk becomes brand risk the moment personal data crosses the contract line.
Where the Investigation Stands
No group has claimed responsibility for the Steam data breach or the wider intrusion. No public ransom demand has surfaced, and CEVA has not described the initial access route. That silence is normal this early, and it does not rule out an extortion attempt later.
CEVA isolated the affected systems, pulled them offline and brought in outside investigators. The company says the rest of its global network kept running without incident. Dutch authorities have opened an investigation, and Valve is notifying data protection regulators in every affected country.
For customers, the practical work is small but worth doing. Watch delivery-themed messages closely over the next few months, verify anything unexpected through official Steam support channels, and treat a correct home address in a message as proof of nothing.
The Steam data breach cost people their contact details, not their accounts. Attackers will now spend months trying to turn the first into the second.
Subscribe to receive the latest blog posts to your inbox every week.