Get all your news in one place.
100's of premium titles.
One app.
Start reading
PC Gamer
PC Gamer
Lincoln Carpenter

Steam user data 'may have been compromised' by a cyberattack targeting Valve's European shipping partner

A Steam logo seen displayed on a smartphone and in the background; Distant view of the headquarters of Ceva Logistics Europe, formerly Gefco, a French international industrial logistics company.

Earlier this morning, Valve began contacting customers who have purchased Steam hardware in Europe to notify them that one of its regional shipping partners, CEVA Logistics, was the subject of a recent cyberattack that "likely" exposed their personal information.

In its email—shared by notified users on Reddit and elsewhere—Valve said the attack took place sometime between July 29 and August 1, 2026. The company explained that the attackers targeted "specific delivery-related information" that Valve provides to CEVA Logistics in order to fulfill hardware orders for European customers, which the France-headquartered shipping company retains "for up to 90 days after that order."

PSA: European-Logistics Partner for Steam hit in Cyberattack
from r/Steam

In a statement emailed to PC Gamer, Valve confirmed that it first learned of the attack on August 7.

"Over the weekend more details came through that allowed us to assemble a list of customers that we see at risk of having been affected," Valve told PC Gamer. "Though CEVA is still investigating the attack, we wanted to at least send out messaging to all customers we can assume were affected based on what we currently know."

Valve says the name, street addresses, phone numbers, email addresses, and order details of European customers whose orders were fulfilled by CEVA Logistics "may have been compromised."

The company warns that affected users should be vigilant about fraudulent messages masquerading as Valve or a delivery company, and that those attempts might use compromised information to seem genuine. However, Valve says users shouldn't need to change their passwords, and because its shipping partners aren't provided with any customer payment information or other non-delivery details, any unrelated Steam account information should still be secure.

According to FreightWaves reporting, eight CEVA warehouse hubs were affected by the cyberattack, causing shipping delays across Europe for its retail partners.

It's unclear how many users in total have been affected by the breach: Valve itself is still working to get all the details of the cyberattack, as it says it's "pressing CEVA for the full scope of what was taken and how" while it works with data protection authorities in respective European countries. In a statement given to TechCrunch, CEVA says its "thorough investigation" of the incident is still ongoing.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.