Steam Hardware Cyberattack: Valve Warns of Fake Messages
Steam Hardware Cyberattack: Valve Warns of Fake Messages

Valve has warned customers in Europe who purchased Steam hardware that their data was 'likely' compromised in a cyberattack targeting shipping partner CEVA Logistics. The company urges vigilance against fake messages.

Attack Details and Impact

Customers who bought Steam hardware received an email from Valve notifying them that CEVA Logistics was targeted by a cyberattack between July 29 and August 1, 2026. An investigation is ongoing, but Valve stated that 'information about Steam customers' was 'likely compromised'.

The potentially compromised data includes names, street addresses, country, phone number, email address, and details of the ordered product. Passwords and payment details were not affected, as CEVA does not have access to that information.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Valve's Warning and Guidance

Valve advises affected customers to 'expect fake messages' via email, text, or phone that mention hardware orders and appear to come from Steam, Valve, or a delivery company. These messages may quote addresses to appear genuine, but Valve instructs to 'treat all of them as fake'.

Valve is 'pressing CEVA for the full scope of what was taken and how', while CEVA is notifying data protection authorities in affected countries.

Context and Ongoing Shipping

Steam Machines have been shipping to pre-order winners, and Steam Controllers have been sent since May. This incident follows a reported Steam data leak last year, which Valve downplayed as overblown and related to old text messages.

Pickt after-article banner — collaborative shopping lists app with family illustration