If you’ve been holding out on buying Valve’s ludicrously expensive home console, you may have saved yourself from more than an empty wallet. European customers who ordered a Steam Machine or Steam Controller may be the victims of a personal information data breach after one of Valve’s hardware distribution partners was hit by a cyberattack.
CEVA Logistics, the company that helps organize Valve’s European supply chain, informed its partner of the data breach on Aug. 7. A Valve spokesperson told CNET that the company spent the weekend assembling a list of at-risk customers, notifying them about the attack via email on Monday morning.
“Though CEVA is still investigating the attack, we wanted to at least send out messaging to all customers we can assume were affected based on what we currently know,” the spokesperson said.
What Valve currently knows is that the personal information revealed by the cyberattack is likely all delivery-related. CEVA told Valve that the breach revealed customers’ names, countries, street addresses, phone numbers and email addresses. According to Valve, “payment information, passwords and Steam Guard codes” are all safe, since CEVA doesn’t have access to this data.
Because phone numbers and email addresses linked to Steam accounts are openly circulating, Valve warned against phishing attacks that may be looking for additional personal information in the coming days.
Read more: Best Data Removal Services of 2026: Reduce Your Online Presence
“Expect fake messages – email, SMS or phone – that mention your hardware order and appear to come from Steam, Valve or a delivery company,” Valve wrote in its email to affected customers. “They may quote your address back to you to prove they’re genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee or sign in somewhere to ‘verify’ your order. Treat all of them as fake.”
Valve reminded customers that Steam’s support team only handles issues on the official help page and never sends messages over Steam chat or through third-party services. Company employees will also never ask for a customer’s password or Steam Guard codes.
The finer details of the attack currently remain unclear, as there’s no official information available on how many customers were affected, how much data was stolen or how the cyberattack infiltrated CEVA Logistics’ systems. In its statement, Valve said it is “pressing CEVA for the full scope” of the breach.
Alongside CEVA’s internal investigation, authorities in the Netherlands are looking into the attack. A spokesperson for the Dutch data protection authority told TechCrunch that the agency has received data breach reports from at least 10 companies in relation to the hack.
In addition to the data breach, FreightWaves reported operations at eight of the company’s warehouses have been affected by the cyberattack, causing potential delays or cancellations to customer orders in the coming days.
CEVA Logistics did not immediately respond to a request for comment.
Tyler is a writer for CNET covering laptops and video games. He's previously covered mobile devices, home energy products and broadband. He came to CNET straight out of college, where he graduated from Seton Hall with a bachelor's degree in journalism. When Tyler's not asking questions or doing research for his next assignment, you can find him in his home state of New Jersey, kicking back with a bagel and watching an action flick or playing a new video game. You can reach him at [email protected]. See full bio









English (US) ·