• Home Article Bought any of that fancy Steam hardware lately? A cyberattack has exposed your personal details – here’s what to do

Bought any of that fancy Steam hardware lately? A cyberattack has exposed your personal details – here’s what to do

Paul McNally

By Paul McNallyManaging Editor

Bought any of that fancy Steam hardware lately? A cyberattack has exposed your personal details – here’s what to do

Valve has begun contacting Steam customers in Europe after a cyberattack against one of its hardware delivery partners resulted in personal information being accessed by attackers.

The incident did not involve a breach of Steam itself. Instead, the attack targeted CEVA Logistics, the company Valve uses to ship physical Steam hardware to customers across Europe. CEVA has also been linked to compromised customer information belonging to several other European retailers following an attack on eight of its warehouses.

According to an email Valve has sent to affected Steam customers, the cyberattack took place between July 29 and August 1, 2026. Valve says it was informed on August 7 that information relating to some of its customers was likely among the data compromised.

The warning applies to customers who recently bought physical Steam hardware in Europe, with CEVA retaining delivery information for up to 90 days after an order has been completed.

That means anyone who has picked up one of Valve’s recent hardware products and received an email from the company should take the warning seriously.

What Steam customer information was compromised?

The information potentially obtained during the CEVA attack includes customers’ names, street addresses, postcodes, cities, countries, phone numbers and email addresses.

Attackers may also have obtained details of which Steam hardware product was ordered and how much it cost.

That last part potentially makes the leak particularly useful for phishing attempts. Rather than sending out a generic fake Steam email, criminals could potentially contact someone knowing their name, address and exactly what piece of Steam hardware they recently bought.

There is some good news, however.

Valve says CEVA does not have access to Steam passwords, Steam Guard codes or payment information, meaning none of those details were exposed during the attack. Information about other Steam purchases was also unaffected.

Valve says customers do not need to change their Steam passwords or make changes to their accounts as a direct result of the breach.

What should you do if you are affected by the Steam hardware data breach?

If you’ve received the warning from Valve, the biggest danger now is likely to be a convincing phishing or delivery scam rather than somebody immediately gaining access to your Steam account.

Valve specifically warns that attackers could contact customers by email, text message or phone while pretending to be Steam, Valve or a delivery company. Because some of your genuine order information may have been taken, these messages could look considerably more convincing than your average dodgy phishing email.

If you believe you’re affected:

  • Be suspicious of emails, calls or text messages mentioning your Steam hardware delivery, particularly ones asking for a redelivery fee, customs payment or account verification.
  • Don’t click links in unexpected Steam or courier messages. If you need to check your Steam account, type the Steam or Steam Support address into your browser yourself.
  • Never give anyone your Steam password or Steam Guard authentication code. Valve says neither Steam Support nor a legitimate courier will ask for them.
  • Be especially wary if somebody quotes your address, phone number or hardware order back to you. Those details being correct no longer proves the message is genuine.
  • Keep Steam Guard enabled. Valve says changing your password isn’t necessary because passwords weren’t exposed, but two-factor authentication remains an important extra layer of protection.
  • Keep an eye on your email and phone for an increase in targeted spam or phishing attempts over the coming weeks.

Valve also stresses that Steam Support deals with account problems through its official support website and will not contact users through Discord, Steam Chat or unsolicited emails asking for login details.

CEVA has isolated the affected systems and brought in external investigators, while Valve says it is pushing the logistics company for more information about exactly what was accessed. Data protection authorities in affected European countries are also being notified.

The wider CEVA incident has already affected other retailers. Reports indicate eight European warehouses were hit, with customers of Dutch retailers bol and De Bijenkorf also warned that personal information may have been accessed. Payment information belonging to those customers was similarly reported as unaffected.

For Steam users, then, there’s no reason to panic or start changing every password in sight. However, if you’ve recently had an expensive piece of Steam hardware delivered, an email or text that appears to know an uncomfortable amount about your order deserves considerably more suspicion than usual.

Paul McNally
Authored by Paul McNally

Paul McNally has been around consoles and computers since his parents bought him a Mattel Intellivision in 1980. He has been a prominent games journalist since the 1990s, spending over a decade as editor of popular print-based video games and computer magazines, including a market-leading PlayStation title. Paul has written high-end gaming content for GamePro, Official Australian PlayStation Magazine, PlayStation Pro, Amiga Action, Mega Action, ST Action, GQ, Loaded, and the The Mirror. He has also hosted panels at retro-gaming conventions and can regularly be found guesting on gaming podcasts and Twitch shows. Believing that the reader deserves actually to enjoy what they are reading is a big part of Paul’s ethos when it comes to gaming journalism, elevating the sites he works on above the norm.