Valve has begun contacting European customers who bought Steam hardware to warn that their personal information was likely exposed in a cyberattack targeting CEVA Logistics, the shipping partner that fulfills hardware orders across the region. The company first learned of the attack on August 7, and it says certain customer data "was likely compromised" as a result.
The attackers targeted "specific delivery-related information" that Valve provides to CEVA Logistics to ship hardware orders, according to a statement Valve emailed to PC Gamer. CEVA, which is headquartered in France, retains that delivery information for up to 90 days after an order, meaning customers who purchased hardware in recent months may be affected.
Valve says it assembled a list of customers it sees at risk after more details emerged over the weekend.
The potentially exposed data includes names, street addresses with postal code and city, phone numbers, and the email address tied to a customer's Steam account. Valve also says the type of product ordered and the total price may have been compromised.
Players in Europe who recently ordered a Steam Controller or Steam Machine could be affected, and the shipping company handles Steam Deck deliveries as well.
Valve is warning affected users to expect fraudulent messages that reference their hardware orders and appear to come from Steam, Valve, or a delivery company. Those attempts may quote a customer's address to seem genuine, ask for a small customs or redelivery fee, or prompt a sign-in to "verify" an order, and Valve says all such messages should be treated as fake.
The company says users do not need to change their Steam passwords, since CEVA never receives payment information, Steam Guard codes, or other non-delivery account details. Valve adds that CEVA is still investigating the incident and has isolated affected systems, taken them offline, and brought in outside investigators, while Valve says it continues pressing the shipping partner for the full scope of what was taken.













