Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Valve says customer data impacted in third-party breach

Major video game publisher Valve has disclosed a cyber incident impacting a third-party shipping partner, with the breach reportedly compromising the data of the publisher’s customers.

Wed, 12 Aug 2026
Valve says customer data impacted in third-party breach

Valve reportedly has begun notifying its European Steam hardware customers that their data was “likely” impacted in a cyber attack on CEVA Logistics, one of the world’s largest global logistics and supply chain firms, and the company responsible for shipping Steam hardware like the Steam Deck consoles out to Valve’s European customers.

“Between July 29, 2026 and August 1, 2026, a cyber attack hit CEVA Logistics, the company that ships Steam hardware to customers in Europe. CEVA is still investigating this attack, but as Valve learned on August 7, certain information about Steam customers, including you, was likely compromised,” a notice to customers reportedly said.

“CEVA receives specific delivery-related information from Steam to be able to ship physical hardware to customers in Europe, and told us these are the details the attacker likely took. Because CEVA retains this information for up to 90 days after that order, we are sending this message to all customers we can assume were impacted.”

 
 

According to the notice, the data impacted includes names, addresses, countries, phone numbers, email addresses, and product details, including type and price.

“Additional information related to your Steam account or other purchases was not impacted. CEVA does not have access to your payment information, passwords, Steam Guard codes or other information,” it said.

Valve warned customers that they should expect fake phishing emails, texts and phone calls from scammers that appear to come from Steam that use the data involved to verify legitimacy.

“They may quote your address back to you to prove they’re genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to ‘verify’ your order. Treat all of them as fake,” it said.

The company also said that account issues are handled exclusively through Steam Support, using the https://help.steampowered.com/ website.

“Never by email, Steam Chat or Discord. Anyone who contacts you elsewhere claiming to be Steam Support is not.

“Every real Steam login page is on store.steampowered.com, www.steampowered.com, steamcommunity.com or help.steampowered.com. Type the address yourself rather than following a link someone sent you,” the release said.

Valve also said that passwords do not need to be changed and that a Valve staffer will never ask for a password.

In terms of what Valve is doing, it said that CEVA has isolated the impacted system, taken it offline, and is now conducting an investigation. Valve itself is pushing CEVA for “the full scope of what was taken” and says it is currently notifying data protection watchdogs in impacted countries.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: