Hey there Legend! Just to bring to your notice that some links and ad banners on this page are affiliates which means that, if you choose to make a purchase, we may earn a small commission at no extra cost to you. We greatly appreciate your support!

Valve CEVA cyberattack warning: what Steam hardware buyers in Europe should do

Valve CEVA cyberattack warning: what Steam hardware buyers in Europe should do

August 12, 2026 Off

Passwords, payment information and Steam Guard codes were not involved, Valve says.

By Ibraheem Adeola

Valve says a cyberattack at CEVA Logistics, its shipping partner for Steam hardware in Europe, may have compromised delivery and order information belonging to some customers.

This is not described as a breach of Steam’s account systems. Valve says CEVA did not have access to customers’ payment information, Steam passwords or Steam Guard codes. The immediate concern is targeted phishing: messages that use genuine delivery details to make a fake fee, delivery confirmation or sign-in request appear credible.

What Valve says happened

According to Valve’s customer notification, CEVA was hit by a cyberattack between July 29 and August 1, 2026. Valve says it learned on August 7 that certain Steam-customer information was likely compromised. PC Gamer reported, citing a statement from Valve, that the company assembled a list of customers it believed could have been affected and sent warnings based on the information available while CEVA’s investigation continued.

Who the Steam hardware warning applies to

Shuhei Yoshida says Steam Machine is ‘hard to recommend to people’ at its current price
Image credit: Valve

The notice concerns customers whose Steam hardware was shipped in Europe through CEVA. It does not establish that every European Steam user, every owner of a particular Steam device or every European hardware order was affected.

Valve has not published an affected-country list, product list, order-date range or customer total. The company says it is pressing CEVA for details about the scope of the incident and how it happened, while also notifying relevant data-protection authorities.

If you received Valve’s incident notice, you are among the customers the company believed could be affected based on the information then available. If you did not receive one, that alone does not establish whether your order was outside the incident because the complete scope has not been disclosed.

The incident involves a fulfilment partner rather than Steam’s storefront or account infrastructure. For more background on the underlying sales and fulfilment model, see our coverage of Valve’s Steam hardware distribution approach in Europe.

What information may have been exposed

Valve says information connected to a Steam hardware purchase and delivery may have been compromised, including:

  • the customer’s name;
  • street address, postal code, city and country;
  • phone number;
  • the email address associated with the customer’s Steam account; and
  • the type and price of the hardware ordered.

Those details could make an impersonation attempt unusually convincing. Someone with the order and delivery information could refer to the correct product or address before requesting a small delivery payment, asking the customer to confirm an address or directing the customer to a fake sign-in page. Valve specifically warns about unexpected email, text and phone messages concerning an order.

Do you need to change your Steam password?

Steam Frame VR
Image credit: Steam

Not solely because of this incident, according to Valve. The company says CEVA did not have access to payment information, passwords, Steam Guard codes or other Steam-account information. Valve also says information about other purchases was not affected.

“You do not need to change your Steam password.”

That is Valve’s guidance for this incident because the company says CEVA did not hold the password or authentication information in question.

Valve’s direction for unexpected order-related messages is equally explicit:

“Treat all of them as fake.”

The warning applies to purported messages from Steam, Valve or a delivery company that refer to the hardware order. A message should not be trusted merely because it includes a real address, phone number, email address or product detail.

What notified customers should do now

  • Do not follow links or call numbers in an unexpected message about a Steam hardware delivery, even if the message includes your address or the product you ordered.
  • Do not pay a requested small fee to release, redeliver or confirm an order through an unsolicited message.
  • Do not sign in to Steam through a link in an order-related email or text. Open Steam independently if you need to check your account.
  • Be especially sceptical of messages that create urgency around delivery, customs charges or account verification.
  • If you want to review your general account protections, use Valve’s official Steam account security recommendations. Valve does not present those recommendations as a requirement to reset a password because of the CEVA incident.

Valve continues to use qualified language: the information was likely or may have been compromised, rather than confirmed as taken for every person who received a notice. The total affected population, countries, products and technical scope remain unresolved while CEVA’s investigation continues.