Valve, the video game publisher and digital distribution platform, has notified customers in Europe that their personal information may have been exposed due to a cyberattack on its logistics partner, CEVA Logistics. The breach, which occurred between July 29 and August 1, 2026, affected systems used to ship Steam hardware to customers across the continent. Valve learned of the incident on August 7 and has since begun contacting affected individuals.

The compromised data includes customer names, postal addresses, phone numbers, and email addresses. Additionally, details regarding the type of Steam hardware ordered and its price may have been accessed. Valve has stated that sensitive information such as payment details, passwords, and Steam Guard codes were not accessed, as CEVA Logistics does not have access to this data. The company is urging customers to be vigilant and expect potential phishing attempts, including fake emails, SMS messages, or phone calls that impersonate Valve or delivery companies. These fraudulent communications may attempt to solicit further personal information or request payment for fictitious delivery or customs fees.

CEVA Logistics, a subsidiary of the CMA CGM Group, handles the distribution of Steam hardware in Europe. The company retains delivery-related information for up to 90 days after an order is fulfilled. This retention period means that customers who purchased Steam hardware in Europe within the last three months could potentially be impacted. Valve is reportedly pressing CEVA Logistics for more details on the extent of the breach and is cooperating with data protection authorities in affected countries. CEVA Logistics has reportedly taken the affected systems offline and engaged external investigators.

This incident is not the first time CEVA Logistics has faced cybersecurity challenges. The company was previously linked to a database breach in late 2025, for which the CoinbaseCartel ransomware group claimed responsibility. The current attack disrupted operations at eight of CEVA's European warehouses.

Valve has advised customers that there is no need to change their Steam account passwords or modify any other account settings as a direct result of this breach. The company is directly emailing affected customers and has made public statements through news outlets and social media platforms like Reddit to disseminate information about the incident. Customers with concerns are encouraged to contact Valve support or CEVA Logistics for further information.

The company is also taking steps to notify data protection authorities in the relevant European countries. The breach underscores the ongoing risks associated with third-party vendor security in the supply chain, particularly for companies that handle physical goods and customer data.