Valve Customer Data Exposed in CEVA Logistics Cyberattack
12.08.26
Valve’s logistics partner, CEVA Logistics, has been hit by a cyberattack, granting unauthorized actors access to the personal data of customers purchasing devices in Europe. Valve has alerted customers to the increased risk of phishing attacks, urging them to exercise extreme caution regarding delivery notifications.
Incident Details and Exposed Data
According to Valve, unauthorized access to the contractor’s systems was detected between July 29 and August 1, with Valve receiving notification of the incident on August 7. Hackers accessed customer information held for order fulfillment purposes (CEVA typically retains this data for up to 90 days).
The compromised data includes:
- Customer names
- Email addresses
- Phone numbers
- Shipping addresses
- Order contents
- Order costs
It is important to note that Steam account passwords, payment details, and Steam Guard two-factor authentication codes remain secure and were not compromised during this attack.

Phishing Risks and Safety Measures
Valve is officially warning its European customers about heightened malicious activity. Users should remain vigilant against phishing attempts via email, SMS, or phone calls, where attackers may impersonate delivery services or Valve representatives. The primary goal of such attacks is to coerce users into paying fake customs duties, delivery fees, or to lure them to malicious phishing websites.
Valve’s expert recommendations:
- Never click links in suspicious emails.
- Always manually enter official addresses (help.steampowered.com, store.steampowered.com) into your browser.
- Use the official desktop Steam client.
- Remember that official support will never ask for your password or Steam Guard code in personal correspondence.
CEVA Logistics has currently isolated the affected systems and engaged third-party security experts to conduct a detailed investigation. Relevant data protection authorities have been promptly notified of the incident.
While the breach at the third-party logistics provider did not impact Steam accounts or payment information, the stolen details are sufficient for sophisticated phishing campaigns. European Valve customers should be especially cautious regarding delivery-related communications and must never disclose their passwords or Steam Guard codes to third parties.
Don't miss interesting news
Subscribe to our channels and read announcements of high-tech news, tes
Oppo A6 Pro smartphone review: ambitious
Creating new mid-range smartphones is no easy task. Manufacturers have to balance performance, camera capabilities, displays, and the overall cost impact of each component. How the new Oppo A6 Pro balances these factors is discussed in our review.
In-Ear headphones Active Noise Cancellation: how Oppo eliminate noise
In-ear headphones remain one of the most popular form factors due to their lightweight design. However, this design is considered one of the most challenging to implement active noise cancellation (ANC). We’ll explain how Oppo solved this problem.
Google Surprise: Pixel 11 and Pixel Watch 5 Pre-orders Surface 8 Hours Early
Google is shaking up its launch schedule: pre-orders for the Pixel 11 and Pixel Watch 5 have been pushed up by eight hours. Fans can now place orders at 10:00 ET, well before the evening presentation.
Valve Customer Data Exposed in CEVA Logistics Cyberattack
A cyberattack on CEVA Logistics has led to the exposure of personal data belonging to some European Valve customers.


