
Steam Security Alert.
Valve Warns European Steam Users of Severe Security Breach
Valve warns European Steam customers of a severe security breach at logistics partner CEVA Logistics, exposing personal shipping details and risking phishing scams.
Highlights
- Valve notified European Steam hardware customers of a severe security breach at third-party logistics partner CEVA Logistics.
- While names, addresses, phone numbers, and purchase details were stolen, payment info and Steam passwords remained entirely secure.
- Valve warned affected users to watch out for targeted phishing scams utilizing their stolen hardware order history and home addresses.
If you recently bought a Steam Deck, Steam Controller, or Steam Machine in Europe, you need to keep a close eye on your inbox. Valve has started contacting players across the region to warn them that their personal information was likely exposed following a severe security breach at CEVA Logistics, the third-party shipping partner responsible for delivering Steam hardware.
The security breach occurred between July 29 and August 1, with the logistics company officially informing Valve of the incident on August 7. Because couriers require your details to complete deliveries and retain these records for up to 90 days, anyone who purchased Steam hardware over the past three months might be affected. The hackers managed to steal a significant amount of personal data, including customer names, full street addresses, postal codes, cities, countries, and phone numbers.
The compromised data also included the email addresses linked to users' Steam accounts and specific purchase details, such as the exact hardware ordered and the total price paid. However, it seems your most highly sensitive account details remain entirely secure. Valve was quick to reassure the community that CEVA Logistics never handles user accounts or processes payments. This means your credit card information, Steam passwords, and Steam Guard security codes were completely out of reach for the attackers.
Despite your account being secure, Valve is heavily cautioning customers to watch out for targeted scams. Armed with actual home address and order history, hackers are likely to attempt to send highly convincing phishing attempts. As for what to look out for, the Valve email stated: “Expect fake messages - email, SMS or phone - that mention your hardware order and appear to come from Steam, Valve or a delivery company. They may quote your address back to you to prove they’re genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to ‘verify’ your order. Treat all of them as fake.”

Steam
Widespread Impact Across European Businesses
To stay safe, the company has reminded players that Steam Support never contacts users through email, Steam Chat, or Discord. They only handle account problems directly through their official help page. Valve encouraged users to avoid clicking on login links and confirmed that legitimate couriers will never ask for your password or Steam Guard code, as per VGC.
Meanwhile, CEVA has isolated the affected servers across its eight impacted European warehouses. The attack has had a widespread impact beyond gaming, forcing other major businesses that rely on CEVA, including Dutch retailers Bol and De Bijenkorf, Ajax, ING, and Ace & Tate, to issue similar warnings.
Unfortunately, data leaks and digital scams have become relatively common on the modern internet. The gaming industry is battling a wave of cyber threats, with NordVPN’s Threat Intelligence unit noting numerous ongoing scams targeting 2026’s biggest game, Grand Theft Auto 6. Hackers are currently using websites to promise fake PC and Android beta keys while phishing for Rockstar Social Club accounts.
Rockstar Games was breached earlier this year in April for internal company data, which followed a far more serious hack in 2023 that resulted in early GTA 6 footage leaking online. Other recent high-profile incidents include a major GameFreak data leak in 2024 and an Insomniac ransomware attack in 2023. Even Valve had a scare last year regarding reports that 89M Steam users’ information had been exposed, though they thankfully confirmed it consisted only of older encrypted SMS authentication messages lacking sensitive details.

Author
Krishna Goswami is a content writer at Outlook India, where she delves into the vibrant worlds of pop culture, gaming, and esports. A graduate of the Indian Institute of Mass Communication (IIMC) with a PG Diploma in English Journalism, she brings a strong journalistic foundation to her work. Her prior newsroom experience equips her to deliver sharp, insightful, and engaging content on the latest trends in the digital world.
Krishna Goswami is a content writer at Outlook India, where she delves into the vibrant worlds of pop culture, gaming, and esports. A graduate of the Indian Institute of Mass Communication (IIMC) with a PG Diploma in English Journalism, she brings a strong journalistic foundation to her work. Her prior newsroom experience equips her to deliver sharp, insightful, and engaging content on the latest trends in the digital world.
Related Articles





