Valve is warning European Steam Machine and Steam Controller customers after logistics partner CEVA was hacked. Here is what data may be exposed and how to protect your Steam account.

Image: dailysecurityreview.com
Valve warns European hardware buyers after a logistics partner attack
Valve has begun warning Steam hardware customers in Europe that personal delivery details connected to recent orders may have been compromised after a cyberattack against CEVA Logistics, the company Valve uses to help distribute hardware across the region. Valve’s own servers and Steam account systems are described in the reports as safe, but the information held by its logistics partner creates a different and very practical risk for Steam Machine owners: convincing delivery scams aimed at people who recently bought Valve hardware.
According to Eurogamer, GameSpot, IGN, Kotaku, and Dexerto, Valve’s customer notice says CEVA received delivery-related information from Steam so it could ship physical hardware to customers in Europe. Valve told affected customers that the attacker likely took those delivery details from CEVA’s systems, not from Valve’s account infrastructure.
That distinction matters for Steam account safety. The Valve Steam Machine data breach being reported is not described by Valve as a Steam password or payment-card compromise. Instead, it is a supply-chain data exposure tied to fulfillment. The exposed data may be enough for scammers to sound unusually credible, because they could know who ordered hardware, where it was going, and how to contact the buyer.
What data may have been exposed, and what Valve says was not affected
Valve’s warning, as quoted by multiple outlets, says the compromised information may include names, street addresses, phone numbers, countries of residence, Steam account email addresses, and Steam hardware purchase details. Eurogamer reports that purchase details could be part of the leak, which is the piece that turns a general phishing risk into a targeted shipment scam.
Dexerto quotes Valve’s message as saying CEVA was given “specific delivery-related information from Steam” to ship hardware in Europe, and that CEVA told Valve these are the details the attacker likely took. GameSpot similarly reports that CEVA retained customer information for up to 90 days, which means names, addresses, phone numbers, and email addresses may have been acquired.
Valve’s notice also draws a clear boundary around what CEVA did not have. Dexerto reports that Valve told customers, “Additional information related to your Steam account or other purchases was not impacted,” and that CEVA does not have access to payment information, passwords, Steam Guard codes, or other account information. GameSpot reports Valve also reminded users that Valve and Steam Support will never ask for passwords or a Steam Guard code.
So the confirmed risk, based on Valve’s warning as reported by those outlets, is exposure of personal and order-related delivery information. The unconfirmed part is the final scope: Valve has not yet publicly detailed exactly how many people were affected or precisely which records were taken.
Who may be affected: Steam Machine, Steam Controller, and possibly wider Steam hardware orders
The core affected group is European customers who recently ordered Valve hardware shipped through CEVA Logistics. Eurogamer frames Valve’s notice around Steam Machine and Steam Controller customers in Europe, and reports that Steam Machines have been shipping for the last couple of months to customers who won Valve’s pre-order lottery, while Steam Controllers are also still shipping. Eurogamer adds that ordering a Steam Controller now will not get customers one until sometime in 2027, underlining how current and active the fulfillment pipeline still is.
GameSpot describes the warning as affecting European owners of the Steam Machine PC. IGN uses a broader formulation, reporting that anyone in Europe who purchased a Steam Deck, Steam Machine, or Steam Controller within the past 90 days may have been potentially impacted, though passwords and payment details are not thought to be at risk. Kotaku also says Valve’s email appears to concern customers who purchased Steam-related hardware in Europe, and notes that the number of affected Steam customers is currently unconfirmed.
The 90-day window comes from Valve’s explanation that CEVA retains delivery information for up to 90 days after an order. Kotaku reasons from that retention period that European customers who purchased a Steam product from late April onward may be at risk. That is an inference based on the retention window rather than a separate confirmed customer list. Valve’s own position, as reported by Eurogamer, is that it is sending the message to all customers it can assume were impacted because CEVA keeps the information for up to 90 days.
The attack timeline is still being clarified
There is one important timing conflict in the reporting. Eurogamer says CEVA Logistics “suffered a breach on 7th August” and later notified Valve. Kotaku, citing the Valve email shared by Steam users, says CEVA was compromised sometime between July 29 and August 1, while Valve first learned of the cyberattack on August 7. Dexerto also refers to a customer-shared Reddit post titled around “July 29th - Aug 1” and quotes Valve saying it learned on August 7 that certain customer information was likely compromised.
Those accounts can be read in two ways. August 7 may be the date Valve learned about the incident, while the compromise itself may have occurred earlier. However, because the source material does not include a full public incident report from CEVA or Valve, the exact timeline should be treated as still under investigation.
Kotaku adds another wrinkle: Dutch outlet NOS reportedly said two separate companies, Bol and De Bijenkorf, were informed of the cyberattack on August 1. That does not prove the scope of Valve customer exposure, but it does show why the timing question is still live. Valve, according to Eurogamer and IGN, says it is pressing CEVA for the full scope of what was taken and how, and is notifying data protection authorities in affected countries.
The main danger is fake delivery contact that uses real order details
Valve’s warning is unusually direct about the type of scam customers should expect. Eurogamer quotes Valve telling customers to “Expect fake messages - email, SMS or phone - that mention your hardware order and appear to come from Steam, Valve or a delivery company.” GameSpot and IGN report the same core warning: scammers may use the exposed information to make a message look tied to a real hardware shipment.
The dangerous part is the proof-of-legitimacy trick. Valve warned that scammers may quote a customer’s address back to them to appear genuine. They may ask the customer to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to “verify” an order. Valve’s instruction, as quoted by Eurogamer, is blunt: “Treat all of them as fake.”
For Steam Machine owners, this is the practical difference between a broad spam campaign and a targeted one. A random message claiming to be about a shipment is easy to ignore if you are not expecting hardware. A message that knows you bought a Steam Machine, has your delivery address, and arrives while Valve hardware is actively shipping is harder to dismiss. That is the attack surface CEVA’s breach appears to create.
Steam account safety steps owners should take now
The first step is to separate shipment anxiety from account action. Based on Valve’s notice as reported by GameSpot and Dexerto, CEVA does not have Steam passwords, payment information, Steam Guard codes, or broader account data. IGN reports there is no need to change Steam passwords or modify account settings because of this incident. That guidance depends on Valve’s current understanding of the breach, which is still being investigated, but it is the account-safety position reflected in the available reporting.
The stronger immediate defense is behavioral. If you receive an email, text, or phone call about a Steam Machine, Steam Controller, Steam Deck, customs charge, redelivery fee, failed delivery, or order verification, do not use links, payment pages, phone numbers, or sign-in prompts from that message. Valve’s warning says to treat such contact as fake, especially if it asks for money, credentials, or verification through an external sign-in flow.
Do not share your Steam password or Steam Guard code with anyone claiming to represent Valve, Steam Support, a courier, or a customs handler. GameSpot reports that Valve specifically says neither Valve nor Steam Support will ever ask for passwords or a Steam Guard code. That remains the cleanest rule in this incident: anyone asking for those details is not helping with your delivery.
If you are uncertain about an order, go through the official Steam client, the official Steam website, or Steam Support directly rather than following a link from a message. The source material does not provide a new Valve-run verification tool for affected shipments, so the safest approach is to avoid inbound prompts and initiate any account or support action yourself through known official channels. Steam Machine owners should also warn anyone else in the household who might answer calls or texts connected to deliveries, because the exposed data may include the address and phone number tied to the order.
Valve still needs CEVA’s full scope before customers can close the book
The unresolved issue is scope. Kotaku reports that neither Valve nor CEVA had released a broad public statement at the time of its article and that Valve was instead emailing customers who may be affected. Eurogamer reports that CEVA continues to investigate the attack, while Valve is pressing CEVA for the full scope of what was taken and how. IGN also reports that Valve is notifying data protection authorities and warning customers to remain vigilant in the days and weeks ahead.
That leaves Steam Machine owners in a familiar modern hardware bind. Valve’s account platform may be intact, but the physical delivery chain still carries personal information that can be weaponized. The Steam Machine launch, according to GameSpot, began in June with a starting price of $1050 and sold out quickly. Eurogamer reports Steam Machines have been shipping to pre-order lottery winners over the last couple of months. Those conditions create a large pool of excited buyers waiting for high-value hardware, which is exactly the kind of audience delivery scammers like to target.
For now, the most accurate summary is narrow but serious: this is a Valve logistics partner hack, not a confirmed Steam account breach. Steam Machine personal details may have been stolen, including contact and delivery information that can make scams sound real. Until Valve and CEVA finish defining the breach, affected European hardware buyers should assume any unexpected delivery-related contact is hostile and keep all Steam account credentials out of every conversation.
