Valve has issued a formal warning to its Steam customers in Europe following a cybersecurity breach that affected their logistics partner, CEVA Logistics. This incident, which occurred between July 29 and August 1, 2026, may have compromised personal information of users who purchased hardware like the Steam Machine and Steam Controller.
On August 7, 2026, Valve confirmed the data compromise after receiving initial reports. The information at risk includes detailed customer data such as names, full addresses, postal codes, cities, countries, phone numbers, email addresses, as well as specific details about the products ordered and their purchase prices.
Investigation Status
CEVA Logistics is currently investigating the breach. As of Valve’s announcement on August 7, it is believed that certain Steam customer data, including that of affected users, may have been compromised. However, Valve has clarified that this incident is limited to CEVA's data storage systems and did not involve a breach of the main Steam account database.
Data Security Measures
Importantly, CEVA was not granted access to the most sensitive user data, such as passwords, payment methods, or Steam Guard credentials. Additional information related to Steam accounts or other purchases remains unaffected. While the accounts themselves are safe from direct hacking attempts, the most significant threat to impacted users is social engineering scams, commonly known as phishing.
Phishing Threats Explained
Individuals with access to transaction histories and personal data can create convincing fake messages that appear to be from Steam or delivery services. With Valve actively expanding its hardware ecosystem through devices like the Steam Machine and Steam Controller, specific details about customer orders become valuable leverage for scammers.
Users may receive fraudulent messages via email, SMS, or phone calls, claiming to be from Steam, Valve, or shipping companies. These messages might reference the recipient's address to seem authentic and may request confirmation of delivery, payment of additional customs charges, or a visit to a site to 'verify' an order. All such communications should be treated as scams.
Recommendations for Users
Valve urges all users to ignore suspicious links from SMS or emails and to rely solely on official Steam Support channels for assistance. This breach serves as a reminder that consumer data security heavily relies on the reliability of third-party supply chains associated with major platforms.
Source: https://www.esports.id/read/data-pembeli-steam-hardware-bocor-valve-ingatkan-ancaman-phishing-19263



