Steam user data 'may have been compromised' by a cyberattack targeting Valve's European shipping partner
An attack targeting CEVA Logistics "likely" exposed the personal information of European customers who ordered Steam hardware, Valve says.
Earlier this morning, Valve began contacting customers who have purchased Steam hardware in Europe to notify them that one of its regional shipping partners, CEVA Logistics, was the subject of a recent cyberattack that "likely" exposed their personal information.
In its email—shared by notified users on Reddit and elsewhere—Valve said the attack took place sometime between July 29 and August 1, 2026. The company explained that the attackers targeted "specific delivery-related information" that Valve provides to CEVA Logistics in order to fulfill hardware orders for European customers, which the France-headquartered shipping company retains "for up to 90 days after that order."
PSA: European-Logistics Partner for Steam hit in Cyberattackfrom r/Steam
In a statement emailed to PC Gamer, Valve confirmed that it first learned of the attack on August 7.
"Over the weekend more details came through that allowed us to assemble a list of customers that we see at risk of having been affected," Valve told PC Gamer. "Though CEVA is still investigating the attack, we wanted to at least send out messaging to all customers we can assume were affected based on what we currently know."
Valve says the name, street addresses, phone numbers, email addresses, and order details of European customers whose orders were fulfilled by CEVA Logistics "may have been compromised."
The company warns that affected users should be vigilant about fraudulent messages masquerading as Valve or a delivery company, and that those attempts might use compromised information to seem genuine. However, Valve says users shouldn't need to change their passwords, and because its shipping partners aren't provided with any customer payment information or other non-delivery details, any unrelated Steam account information should still be secure.
According to FreightWaves reporting, eight CEVA warehouse hubs were affected by the cyberattack, causing shipping delays across Europe for its retail partners.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
It's unclear how many users in total have been affected by the breach: Valve itself is still working to get all the details of the cyberattack, as it says it's "pressing CEVA for the full scope of what was taken and how" while it works with data protection authorities in respective European countries. In a statement given to TechCrunch, CEVA says its "thorough investigation" of the incident is still ongoing.
2026 games: All the upcoming games
Best PC games: Our all-time favorites
Free PC games: Freebie fest
Best FPS games: Finest gunplay
Best RPGs: Grand adventures
Best co-op games: Better together

Lincoln has been writing about games for 12 years—unless you include the essays about procedural storytelling in Dwarf Fortress he convinced his college professors to accept. Leveraging the brainworms from a youth spent in World of Warcraft to write for sites like Waypoint, Polygon, and Fanbyte, Lincoln spent three years freelancing for PC Gamer before joining on as a full-time News Writer in 2024, bringing an expertise in Caves of Qud bird diplomacy, getting sons killed in Crusader Kings, and hitting dinosaurs with hammers in Monster Hunter.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.
