BELLEVUE, Wash. — The email from Valve arrived in Steam hardware customers’ inboxes on Sunday, carrying a disclosure most had no reason to anticipate: their names, addresses, phone numbers, and email addresses had been stolen. Not from Steam’s own systems. From the logistics company that shipped their orders.
CEVA Logistics, a wholly owned subsidiary of CMA CGM Group, the world’s third-largest container shipping company by capacity, suffered a cyberattack between July 29 and August 1, 2026. The attackers accessed servers containing delivery records for Steam Machine and Steam Controller purchases shipped to customers across Europe. Valve says it was notified of the breach on August 7, and began sending disclosure emails to affected customers on the same day.
According to Valve, the stolen data covers names, physical addresses, phone numbers, email addresses, and product details: specifically the type of hardware ordered and what the customer paid for it. The exposure does not include Steam account credentials, passwords, payment information, or Steam Guard codes. That boundary is significant. The breach was contained to the delivery-related data CEVA held on Valve’s behalf, not to anything stored inside Steam itself.
“CEVA receives specific delivery-related information from Steam to be able to ship physical hardware to customers in Europe,” Valve said in its notification to customers, “and told us these are the details the attacker likely took.”
The scope of the breach is tied to a particular CEVA data retention policy. The company holds delivery information for up to 90 days; that window defined which customers Valve needed to reach. No figure has been given for how many accounts fall within that range.
The immediate concern is not what was taken. It is what follows. Names, home addresses, phone numbers, and email addresses are the raw inputs of phishing campaigns. They allow an attacker to construct a message that sounds plausible: a customs delay requiring payment, a delivery re-confirmation, a flag on a recent Steam purchase. Valve’s notification anticipated this directly. “We’re sending this notice because people who had your information may contact you impersonating Steam or a delivery company,” the company wrote, “asking you to provide your payment information or to click on links.” The advice was blunt: “Treat all of them as fake. You do not need to change your Steam password.”

That framing reflects both the reality of the breach and an honest acknowledgment of its limits. Valve can close the technical exposure, since CEVA no longer holds the relevant data once its retention window closes, but it cannot intercept phishing attempts that may already be in motion.
The breach appears to extend well beyond Steam customers. Reports from multiple technology outlets indicate that the same CEVA cyberattack affected other companies using the logistics firm’s network, including banks and major retailers. CEVA operates at considerable scale: the company manages more than 1,000 warehouses globally, processes approximately 15 million shipments per year, and reported revenue of $18.3 billion in 2025, according to BleepingComputer. Its parent, CMA CGM, handles millions of shipping containers annually across routes spanning more than 160 countries.
For Valve, the incident arrives as the company continues to build out its hardware lineup. The Steam Machine, which launched at $1,049 in June with considerable fanfare and some uncomfortable caveats about processing benchmarks, drew Valve into the kind of physical retail and logistics infrastructure it had long avoided. That infrastructure comes with exposure: every shipment is a data record held by a third party, and every third party is a potential point of failure.
This is not the first time fraud has complicated Valve’s hardware business. The company stopped restocking physical Steam gift cards at retail stores earlier this year, citing an unwinnable battle with scammers who consistently adapted faster than Valve’s own countermeasures. That decision came after the Federal Trade Commission reported that older Americans lost $2.4 billion to fraud in 2024, with gift cards among the most common payment instruments used against victims.
Nintendo encountered a version of this problem in June, when attackers claimed to have stolen nearly 860 megabytes of employee data by breaching TINYpulse, a human resources platform Nintendo uses internally. The common thread across these incidents is third-party exposure: the company whose name appears on the product is not always where the attack lands.
CEVA had not publicly acknowledged the incident as of Sunday. No statement appeared on the company’s website, and no threat actor has publicly claimed responsibility. Valve said it is pressing CEVA for the full scope of what was taken and how. The company has also begun notifying data protection authorities in the affected European countries. How the attackers gained access to the servers and whether any of the stolen data has already been put to use remain open questions.
For Steam hardware customers in Europe who received Valve’s notification, the practical response is narrow but important: ignore unexpected delivery-related communications, avoid clicking links in unsolicited messages about recent purchases, and report anything suspicious through Steam’s support system. Valve’s assurance that no passwords need changing is meaningful within its scope. The breach does not touch game libraries, stored payment methods, or account balances. What it does touch is the combination of personal details that makes a convincing follow-up message possible. That is the exposure that lingers after the servers are secured.

