Overview
- A cyberattack on CEVA Logistics between July 29 and August 1, 2026 likely exposed delivery records for Steam hardware orders, a fact Valve says it learned on August 7.
- The data likely taken includes names, street addresses, phone numbers, email addresses tied to Steam accounts, and the type and price of the ordered hardware.
- Valve has begun emailing European hardware buyers to warn them and says CEVA has isolated affected systems, brought in outside investigators, and informed data protection authorities.
- Customers should expect highly targeted scams by email, SMS, or phone that may quote real order details; Valve says payment data, Steam passwords, and Steam Guard codes were not stored with CEVA so those items were not exposed.
- The incident disrupted at least eight CEVA European warehouses, affected multiple retailers that use CEVA, and underscores wider supply‑chain risk while the full scope and number of affected customers remain unknown.