Steam hardware buyers in Europe started receiving data breach notices this week after attackers broke into CEVA Logistics, the shipping company Valve uses to deliver Steam Decks and other hardware. The steam data breach exposed names, addresses, phone numbers, email addresses, and order details. Valve says no passwords or payment data were taken. For any team that hands personal data to a logistics partner, this incident is a reminder that your security is only as strong as the vendors who touch your orders.
What Happened
CEVA Logistics is a fully owned subsidiary of CMA CGM Group, the world's third largest shipping company. It runs about 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in revenue in 2025. Attackers had access to CEVA's servers between July 29 and August 1, 2026, long enough to pull the delivery data CEVA keeps for Steam orders.
Valve says CEVA retains shipping information for up to 90 days after an order, which is why notifications went out to customers who ordered within that window. Valve learned about the exposure on August 7 and started emailing affected customers on August 10. Reports on Reddit and ResetEra confirm the notices went out widely across Europe.
The stolen data includes names, addresses, phone numbers, email addresses, and the type and price of ordered products. CEVA does not hold payment information, passwords, or Steam Guard codes, so Valve confirmed those were not part of the breach.
Company Response
Valve's notification emails are unusually direct. The company said it is pressing CEVA for the full scope of what was taken and how, and it is notifying data protection authorities in the affected countries. CEVA has isolated the affected systems, taken them offline, and brought in outside investigators.
Valve also told customers not to change their Steam passwords, since Steam accounts were not accessed. The immediate risk is phishing. Attackers now hold real addresses and order details, so scam messages can quote your address back to you to look legitimate. Requests to confirm a delivery, pay a customs fee, or sign in somewhere to verify an order should be treated as fake.
Why This Matters to Developers
The breach hits developers on two levels. First, many of us ordered Steam Decks, Steam Link, or other hardware directly from Valve, which means a chunk of the developer community is in the notification pool. Second, the incident is a textbook third party breach: the compromise happened at CEVA, not at Valve. Steam accounts were never touched, but personal data still leaked because a vendor down the chain was weak.
This pattern keeps repeating in 2026. Breaches at shipping and logistics firms ripple outward to retailers, banks, and platform companies that trusted the vendor with delivery data. CEVA also notified European retailers including bol and De Bijenkorf after the attack disrupted operations at eight of its warehouses.
What Security Teams Should Do
- Question why vendors retain personal data at all. CEVA kept delivery details for 90 days, which expanded Valve's notification pool. Retention should have a business reason and an expiry.
- Treat vendor breaches as your problem. When a partner is compromised, assume your customers' data was taken and plan notifications with the vendor early, not after the story breaks.
- Watch for personalized phishing after any breach. Stolen addresses and order histories make scams far more convincing. Warn your users specifically about data the attacker could quote back.
- Review your own third party risk program. Logistics, payroll, and support vendors handle sensitive data on your behalf and rarely get the same scrutiny as core infrastructure.
Technical Analysis of the Attack Vector
CEVA has not said how the attackers gained access. What is known: eight European warehouses were affected, and the Dutch Data Protection Authority is investigating along with law enforcement. Dutch retailer bol said two systems used to process orders from one of its distribution centers were accessed, and it suspended data processing there as a precaution. Some bol products were taken offline temporarily, and some orders were canceled or delayed. De Bijenkorf warned customers that order processing, returns, and refunds could take longer than usual.
This is a favorited target sector. Shipping firms have been hit repeatedly, from Maersk's NotPetya disruption and the Expeditors International incident to Estes Forwarding Worldwide being attacked last summer. Logistics companies hold high value data and run sprawling legacy systems, which makes them an attractive entry point for attackers looking to reach multiple organizations at once.
Frequently Asked Questions
Do I need to change my Steam password?
No. Valve confirmed Steam accounts were not accessed and no passwords or Steam Guard codes were exposed. Changing your password is optional and not required because of this incident.
What data was taken in the breach?
Names, addresses, phone numbers, email addresses, and the type and price of products ordered. Payment information was not stored by CEVA and was not exposed.
How can I spot phishing related to this breach?
Scammers may quote your address or order details to appear genuine. Be suspicious of any message asking you to confirm a delivery, pay a customs or redelivery fee, or sign in somewhere to verify an order. Contact Valve or the delivery company through official channels instead.
Why did I get a notification if my order was months ago?
CEVA retains delivery information for up to 90 days after an order. Valve sent notices to every customer whose data could have been within that retention window when the attackers had access.
Who is investigating the CEVA Logistics attack?
CEVA brought in outside investigators, and the Dutch Data Protection Authority plus other law enforcement agencies are looking into the intrusion.
Key Takeaways
- The Steam breach is a vendor compromise, not an account compromise. CEVA Logistics was hit, and delivery data for European hardware orders leaked.
- Exposed data is limited to names, addresses, phone numbers, emails, and order details. No passwords, payment data, or Steam Guard codes.
- The real threat now is phishing. Scammers have real order information and will use it to impersonate Steam, Valve, and delivery companies.
- For security teams, the lesson is vendor data hygiene: retention periods, third party risk reviews, and fast notification planning when a partner is breached.
Conclusion
The CEVA Logistics breach shows how a compromise at a shipping partner turns into a data breach for a platform that did nothing wrong. Valve handled disclosure cleanly, kept the scope honest, and told customers exactly what to watch for. The rest of us should take the same lesson: every vendor that holds customer data is part of your attack surface, and their security decisions become yours the day they get breached.
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.