cognitive cybersecurity intelligence

News and Analysis

Search

Valve Steam Hardware Buyers Hit by CEVA Logistics Data Breach

Valve Steam Hardware Buyers Hit by CEVA Logistics Data Breach

Valve has confirmed that a cyberattack on CEVA Logistics, its European shipping partner for Steam hardware such as the Steam Deck, Steam Machine, and Steam Controller, exposed customer data belonging to buyers across Europe.

The breach occurred between July 29 and August 1, 2026, and Valve says it learned of the compromise on August 7, prompting the company to notify all customers it believes were affected through a direct security email.

According to Valve’s disclosure, the attacker likely accessed delivery-related information that CEVA retains for up to ninety days after an order is placed.

This includes the customer’s full name, street address, postal code, city, country, phone number, the email address linked to their Steam account, and details about the type and price of the hardware ordered.

Valve has stressed that no Steam account credentials, passwords, Steam Guard codes, or payment information were affected, since CEVA never had access to that data in the first place.

CEVA Logistics Data Breach

The Valve notification is part of a much larger incident affecting CEVA Logistics’ European operations. Reporting from FreightWaves indicates the attack disrupted eight CEVA warehouses and caused shipping delays for numerous retail clients, with the intrusion first flagged to affected customers on August 1.

Dutch e-commerce giant Bol and department store De Bijenkorf both confirmed exposure of customer names, addresses, phone numbers, email addresses, order numbers, and purchased item details, though payment credentials remained untouched.

The fallout has since widened to include football club Ajax, bank ING, and eyewear retailer Ace & Tate, all of which rely on CEVA for order fulfillment and have separately notified customers and regulators, including the Dutch Data Protection Authority.

Notably, this is not CEVA’s first brush with attackers. A threat group known as CoinbaseCartel claimed responsibility for a separate, more extensive CEVA breach discovered in September 2025, allegedly exfiltrating full database schemas covering client accounts, costs, VAT numbers, and financial data. It remains unclear whether the current incident is connected to that earlier compromise or represents a fresh intrusion.

Security researchers warn that the combination of real names, home addresses, phone numbers, and specific purchase details creates ideal conditions for highly convincing phishing and delivery-fraud campaigns, particularly given how easily generative AI tools can now personalize scam messages.

Steam users who receive Valve’s notification should expect a rise in fake delivery, refund, or account-verification emails referencing their actual order details, and should treat any unsolicited message asking for payment, login codes, or personal verification as suspicious.

Valve has advised customers to verify communications only through official Steam channels and to remain alert for follow-up scam attempts exploiting the leaked shipping data.

The incident underscores a persistent weakness in digital supply chains: even when a primary vendor like Valve maintains strong internal security, third-party logistics partners handling physical fulfillment can become the weakest link, exposing customer data far beyond the breached company’s own walls.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Valve Steam Hardware Buyers Hit by CEVA Logistics Data Breach appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts