Valve warns Steam hardware buyers their data leaked, but not from Steam
A cyberattack on CEVA Logistics, the company that ships Steam hardware in Europe, exposed delivery details for recent buyers of the Steam Deck, Machine, and Controller. Steam accounts and payment info were not touched. Valve is warning affected customers to watch for convincing scam messages.
If you bought Steam hardware in Europe recently, Valve wants you to know your delivery details may have been stolen, though the leak didn’t come from Steam itself.
The breach hit CEVA Logistics, the shipping company Valve uses to deliver hardware like the Steam Deck, Steam Machine, and Steam Controller to European customers. Attackers had access to CEVA’s systems between July 29 and August 1, and Valve learned on August 7 that some Steam customer information held by the shipper was likely taken. The company has been emailing affected buyers since August 10.
The good news is about what wasn’t exposed.
What was, and wasn’t, taken
The compromised data is limited to what’s needed to ship a package.
That means names, street addresses, postal codes, cities, countries, phone numbers, email addresses, and the type and price of the hardware ordered. It’s real personal information, but it’s delivery data, not account data. Critically, CEVA never had access to payment details, Steam passwords, or Steam Guard codes, so none of that was in the breach.
Valve has been explicit that customers do not need to change their Steam passwords or touch their account settings because of this. Your Steam account itself wasn’t the target and wasn’t reached. If you get a message telling you to urgently reset your Steam password over this breach, that message is itself probably a scam.
The real danger: convincing scams
The reason Valve is warning people isn’t account security. It’s phishing, and this leak makes phishing more dangerous.
Because the attackers may know your name, your address, exactly which piece of Steam hardware you ordered, and what you paid for it, any scam message they send can be tailored to look completely legitimate. A fake email or text could reference your actual Steam Machine order and demand a “customs fee” or “redelivery charge,” and it would carry details a random phishing attempt never could. That specificity is what turns a leak of “just” shipping data into a genuine risk.
Valve’s guidance is the standard, sensible kind: be suspicious of any unexpected message about your hardware delivery, especially ones asking for a payment or a fee, and don’t click links in surprise emails from “Steam” or a courier. When in doubt, go to Steam directly rather than through a link someone sent you.
Who’s affected, and what it means
The scope is defined by how long the shipper keeps records.
CEVA holds delivery information for up to 90 days after an order, so Valve is notifying anyone who bought Steam hardware shipped through Europe roughly since early May. The total number of affected customers hasn’t been disclosed, and CEVA is still investigating the full extent. Valve says it’s notifying data-protection authorities across the affected European countries, as the law requires.
The bigger takeaway is a familiar one: your data is only as secure as the least-secure company that touches it. Valve didn’t get hacked, but a company in its shipping chain did, and that was enough to put customers’ personal details in an attacker’s hands. It lands at an awkward moment, too, just after the Steam Machine launched and as Valve pushes further into selling physical hardware. For buyers, the practical response is simple. Nothing to change on your account, but for the next while, treat any message about your Steam hardware order with real suspicion.
Article compiled and edited by Derek Gibbs (entertainment editor) and the Clownfish TV newsroom.
D/REZZED is part of Clownfish TV. For more news, views, and rants on gaming, tech, and pop culture, visit clownfishtv.com. Watch the show on YouTube at @ClownfishTV where new episodes drop daily. Subscribe to the Clownfish TV podcast on Apple Podcasts, Spotify, iHeart, and wherever else you get your podcasts. Sign up for the free newsletter at more.clownfishtv.com.
Hat Tips:
Tom’s Hardware (August 2026), verified for the CEVA Logistics cyberattack, the July 29-August 1 window, Valve learning on August 7, the delivery-only data scope, and the “expect fake messages” warning
PC Guide (August 2026), verified for the affected hardware (Steam Deck, Machine, Controller), the exact exposed fields, the confirmation that payment info, passwords, and Steam Guard codes were not accessed, and Valve’s no-need-to-change-passwords guidance
VideoCardz (August 2026), verified for the 90-day CEVA retention window, both Steam Machine and Controller customers receiving warnings, and Valve notifying European data-protection authorities
GamesHub and PC Guide (August 2026), verified for the phishing risk, the customs/redelivery-fee scam example, and the advice to avoid links in unexpected Steam or courier messages


