Steam Machine buyers just learned their shipping data got swept up in a logistics breach
Valve's European delivery partner CEVA Logistics was hit by a cyberattack, exposing names, addresses, and phone numbers tied to fresh hardware orders.
Written by OutOfToken AI
August 10, 2026 · 4 min read · Synthesized from reporting by The Verge · How this works
Valve has started emailing European customers who ordered its new Steam Machine or Steam Controller, warning them that a cyberattack on shipping partner CEVA Logistics may have exposed their personal information. The compromised data reportedly includes names, home addresses, phone numbers, email addresses, and details of the products ordered.
What CEVA actually had on file
CEVA Logistics handles physical delivery of Steam hardware across Europe, which means Valve routes specific shipping-related customer details to the company to get boxes to doorsteps. Valve says CEVA retains that delivery information for up to 90 days after an order is placed, and it's this retained window of data that appears to have been accessed in the breach.
Who's affected
Because hardware reservations for the Steam Machine and Steam Controller only opened weeks before the breach window, the pool of affected customers is likely limited to recent European buyers rather than Valve's broader user base. Reports gathering online suggest both Steam Machine and Steam Controller purchasers received the same notification email, indicating the breach wasn't isolated to a single product line.
"Valve says it is "pressing CEVA for the full scope of what was taken and how," and is still investigating the extent of the exposure."
No Steam accounts, no payment data
Valve has been explicit that the breach did not touch Steam account credentials, passwords, or payment information — the exposure is confined to the delivery data CEVA held for shipping logistics. That distinction matters: while a leaked home address and phone number is a real privacy risk, it's a different category of harm than compromised login credentials or financial details.
A pattern of third-party exposure, not a Steam hack
This incident lands in the same general territory as an earlier 2025 episode where leaked SMS authentication codes tied to Steam phone numbers sparked panic about a "Steam breach," only for investigation to show Valve's own servers were never touched. The CEVA breach follows a similar shape — the vulnerability sits with a third-party vendor handling peripheral data, not with Valve's core platform infrastructure.
Valve says it's continuing to work with CEVA to determine exactly what was taken and how the intrusion happened, though it hasn't detailed a timeline for that investigation. For now, affected customers should watch for phishing attempts referencing their real names, addresses, or order details, since that's the kind of information that makes scam emails convincing.
Editorial Note
The research corroborates all major claims in the article regarding what data was exposed (names, addresses, phones, emails, product details), that CEVA retains data for 90 days, and that Steam's own systems were not breached. The article's framing distinguishing this from broader account credential breaches is supported by the sources. The only unverified detail is the specific breach date range (July 29-August 1), which sources confirm occurred but do not provide precise dates.
Claim Tracker
AI-assessed
Research sources confirm a CEVA breach occurred and affected shipping data, but none of the provided sources specify the exact July 29-August 1 date range.
Sources 1, 2, and 3 all confirm these specific data categories were exposed: names, addresses, phone numbers, email addresses, and product type/price information.
Source 1 directly quotes: 'Because CEVA retains this information for up to 90 days after that order, we are sending this message to all customers we can assume were impacted.'
Source 1 confirms no payment information or passwords were compromised. Sources 4 and 6 corroborate from the earlier 2025 SMS incident that password/account credential breaches were ruled out.
Sources 2 and 3 both confirm that reports from users show both Steam Machine and Steam Controller customers received the warning notification.
Ask AI about this story
// discussion
sign in to join the discussion
