Steam Hardware Customers in Europe Warned of Phishing Risks After CEVA Logistics Cyberattack
Valve has alerted European customers who purchased Steam hardware such as the Steam Deck or Steam Machine of potential phishing attempts following a cyberattack on its logistics partner, CEVA Logistics. The breach, detected on August 7, 2026, occurred between July 29 and August 1, exposing customer data held by CEVA for order fulfillment.
The compromised information includes names, addresses, phone numbers, email addresses, and details about ordered products (type and price). However, Valve confirmed that sensitive data such as payment details, passwords, and Steam Guard codes was not accessed, as CEVA does not store this information.
Valve warns customers to expect fraudulent messages via email, SMS, or phone, impersonating Steam, Valve, or delivery services. Attackers may demand fake customs or delivery fees or direct victims to phishing portals. Valve advises verifying URLs (e.g., help.steampowered.com for support) and avoiding embedded links in suspicious messages. The company also reiterated that legitimate Steam communications will never request passwords or Steam Guard codes.
CEVA has isolated the affected systems, notified data protection authorities, and engaged external investigators to assess the incident. The breach underscores the risks of third-party supply chain attacks, even when primary platforms remain secure.
CEVA Logistics cybersecurity rating report: https://www.rankiteo.com/company/ceva-logistics
"id": "CEV1786364851",
"linkid": "ceva-logistics",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'European customers who '
'purchased Steam hardware',
'industry': 'Gaming, E-commerce',
'location': 'Europe',
'name': 'Valve (Steam)',
'type': 'Technology Company'},
{'industry': 'Supply Chain, Logistics',
'name': 'CEVA Logistics',
'type': 'Logistics Provider'}],
'attack_vector': 'Third-party Supply Chain Attack',
'customer_advisories': 'Valve has warned European Steam hardware customers '
'about potential phishing attempts via email, SMS, or '
'phone, impersonating Steam, Valve, or delivery '
'services.',
'data_breach': {'personally_identifiable_information': 'Names, addresses, '
'phone numbers, email '
'addresses',
'sensitivity_of_data': 'Moderate (PII exposed, but no payment '
'or authentication data)',
'type_of_data_compromised': 'Personally Identifiable '
'Information (PII), Order '
'Details'},
'date_detected': '2026-08-07',
'description': 'Valve has alerted European customers who purchased Steam '
'hardware such as the Steam Deck or Steam Machine of potential '
'phishing attempts following a cyberattack on its logistics '
'partner, CEVA Logistics. The breach exposed customer data '
'held by CEVA for order fulfillment, including names, '
'addresses, phone numbers, email addresses, and details about '
'ordered products (type and price). Valve confirmed that '
'sensitive data such as payment details, passwords, and Steam '
'Guard codes was not accessed. Customers are warned to expect '
'fraudulent messages impersonating Steam, Valve, or delivery '
'services.',
'impact': {'brand_reputation_impact': 'Potential reputational damage to Valve '
'and CEVA Logistics',
'data_compromised': 'Names, addresses, phone numbers, email '
'addresses, product details (type and price)',
'identity_theft_risk': 'Moderate (PII exposed)',
'operational_impact': 'Isolation of affected systems, engagement '
'of external investigators',
'payment_information_risk': 'None (payment details not '
'compromised)',
'systems_affected': 'CEVA Logistics order fulfillment systems'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Third-party supply chain attacks pose significant risks '
'even when primary platforms remain secure. Importance of '
'verifying communications and avoiding embedded links in '
'suspicious messages.',
'motivation': 'Phishing (Financial Gain)',
'post_incident_analysis': {'corrective_actions': 'Isolation of affected '
'systems, engagement of '
'external investigators, '
'notification of data '
'protection authorities, and '
'customer advisories',
'root_causes': 'Cyberattack on third-party '
'logistics provider (CEVA '
'Logistics) with access to customer '
'order data'},
'recommendations': 'Customers should verify URLs (e.g., '
'help.steampowered.com), avoid embedded links in '
'suspicious messages, and never share passwords or Steam '
'Guard codes. Companies should enforce stricter '
'third-party security assessments and monitoring.',
'references': [{'source': 'Valve Customer Advisory'}],
'regulatory_compliance': {'regulatory_notifications': 'Data protection '
'authorities notified'},
'response': {'communication_strategy': 'Customer advisories issued by Valve, '
'warning of phishing risks',
'containment_measures': 'Affected systems isolated',
'third_party_assistance': 'External investigators engaged'},
'stakeholder_advisories': 'Valve and CEVA Logistics have issued warnings to '
'stakeholders about the breach and phishing risks.',
'title': 'Steam Hardware Customers in Europe Warned of Phishing Risks After '
'CEVA Logistics Cyberattack',
'type': 'Data Breach'}