Valve Warns European Steam Hardware Buyers After Cyberattack

Valve has spent more than two decades building Steam into the center of PC gaming, while newer hardware such as the Steam Deck, Steam Machine, and Steam Controller has expanded the company’s reach. That hardware business is now facing a security problem: CEVA Logistics, the company responsible for distributing Steam hardware across Europe, suffered a cyberattack that may have exposed personal details belonging to recent customers.

What Happened to the Steam Hardware Distributor

Valve notified users in Europe on August 10 after CEVA reported the incident to the company on August 7. The attack occurred between July 29 and August 1, according to the warning. CEVA handles fulfillment and distribution for Steam-branded hardware in the region, meaning the incident affects some customers through their purchase and delivery records rather than through Steam’s core account systems.

The potentially exposed information includes a customer’s real name, postal address, country, telephone number, and email address. Valve said the breach did not provide access to Steam account passwords or payment information, because CEVA does not have access to those details.

Which Steam Customers May Be Affected

Valve said European users who purchased Steam hardware within 90 days of the attack should receive an email if their information may have been involved. The notice specifically concerns recent buyers of products such as the Steam Machine and Steam Controller, although the source does not give a confirmed number of affected customers.

The exposed contact details create a risk beyond unwanted messages. Valve warned that criminals could use them to make convincing claims about pending hardware orders. Potential scams may arrive by email, text message, or phone call and could falsely appear to come from Valve, Steam, or one of the companies involved in delivery.

Valve Warns Against Order Verification Scams

Users should treat any unexpected request for an additional payment or a website login as fraudulent, particularly when it refers to a Steam hardware shipment. Valve instructed recipients to disregard such messages rather than attempting to verify an order through links or contact details supplied by the sender.

The warning comes as Valve continues supporting its hardware lineup despite higher component costs connected to the ongoing DRAM shortage. Steam Deck has received features including HDR support for Steam Remote Play and experimental AV1 streaming support. Meanwhile, the Steam Machine’s entry price was listed at $1,049, and Valve has warned that worsening memory costs could push that price higher.

A Wider Reminder for Gaming Accounts and Purchases

The CEVA incident follows other recent security concerns affecting gaming customers. In May 2026, several PlayStation Network accounts were compromised using a PSN account ID and transaction details, even though no phishing attempt had been made. Sony subsequently advised users to be careful when sharing sensitive information online.

For Steam customers, the immediate priority is to watch for suspicious communications tied to hardware orders and avoid sharing passwords, payment details, or login codes. Valve’s statement separates the logistics breach from Steam account security, but leaked delivery information can still give attackers enough context to make targeted scams appear credible.

Key points

  • CEVA Logistics reported a cyberattack affecting its European Steam hardware distribution operations.
  • The incident took place between July 29 and August 1, with Valve issuing its warning on August 10.
  • Names, addresses, countries, phone numbers, and email addresses may have been exposed.
  • Steam passwords and payment methods were not accessible to CEVA, according to Valve.

Confirmed incident timeline

Date Event
July 29-August 1 The cyberattack on CEVA took place.
August 7 CEVA reportedly notified Valve of the breach.
August 10 Valve alerted potentially affected users across Europe.

Expert View

The incident highlights a less obvious security risk in modern gaming: hardware purchases involve logistics partners that may hold enough personal information to support targeted fraud, even when platform accounts remain protected. For Valve and other platform companies, clear warnings and rapid guidance will be important as digital storefronts increasingly depend on external fulfillment networks.