The cyberattack on CEVA Logistics' systems occurred between July 29 and August 1, 2026 . Valve learned of the compromise on August 7, 2026 and immediately began contacting affected customers who had purchased Steam hardware — including the Steam Deck, Steam Machine, and Steam Controller — for delivery in Europe
.
CEVA Logistics, a global shipping and logistics company, retained customer delivery information for up to 90 days after an order was placed. This means any European customer who ordered Steam hardware from approximately late April 2026 onward fell within the exposure window .
According to Valve's security notification, the attackers likely accessed CEVA's servers and stole the following categories of information for affected hardware orders :
Valve explicitly stated that the breach did not expose the following, which it never shares with shipping partners :
Valve told affected customers there was no need to change passwords or account settings as a result of this incident .
The CEVA Logistics breach was not limited to Valve. According to reporting from TechCrunch, the same cyberattack also impacted multiple European retailers and banks that relied on CEVA for logistics services . CEVA is a global shipping and logistics giant, and the incident is described as a ripple-effect supply chain attack affecting organizations across several sectors
.
Valve's notification included specific warnings about the risk of follow-on phishing attacks. The stolen data — names, addresses, phone numbers, email addresses, and order details — gives attackers everything they need to craft convincing scam messages that appear to come from Valve, a delivery company, or another trusted entity .
If you purchased Steam hardware for delivery in Europe between late April and early August 2026, your information may be in the hands of attackers. Beyond following Valve's phishing guidance, security experts recommend: