Steam hardware buyers' delivery data stolen in Europe

Valve has started warning European customers who bought Steam hardware that their delivery details were stolen, not from Valve, but from the logistics company that ships the boxes. In a notification email sent from August 10, the company said an attack on its shipping partner CEVA Logistics exposed names, home addresses, phone numbers, the email addresses tied to customers' Steam accounts, and the type and price of the hardware ordered. Passwords and payment information were not affected.

The detail matters more than the volume here. A scammer holding your real name, your real address and the fact that you took delivery of a Steam Deck last month can send a message that clears every instinct most people rely on to spot a fake. Malwarebytes set out the timeline and the exposed fields in its write-up of the notice.

What happened, and when

The intrusion at CEVA ran from July 29 to August 1, 2026. Valve learned of it on August 7 and began notifying customers three days later. Because CEVA holds delivery data for around 90 days after shipment, anyone who received a Steam Deck, Steam Controller or Steam Machine in Europe over the past three months may be caught up in it. Neither company has said how many records were involved, so the scale is still unknown. Dutch retailers Bol and De Bijenkorf were reportedly notified of the same CEVA incident on August 1 and warned their own customers.

Why shipping data is worth stealing

Order records are the raw material for convincing follow-on fraud. The usual play is a message or call that quotes the real order and delivery address, then asks for a small customs or redelivery fee, a delivery confirmation, or a sign-in to verify the order. Criminal services have industrialized this: a bulk SMS platform recently seen in the wild slips fake texts into the same thread as a bank's real messages, which removes the last visual cue a recipient has. Malwarebytes says its researchers found more than 7,500 compromised datasets containing over 8.4 billion records on the dark web in the first six months of 2026, so a fresh set of names and addresses does not stay scarce for long.

What affected buyers should do

Valve's advice to customers is blunt: assume that any message referencing a recent Steam hardware order is fake. That applies to email, SMS and phone calls, including the ones that quote your address correctly. Steam Support does not contact users through email, Steam Chat or Discord, and handles account problems only through its own help page, so an unsolicited approach claiming to be Steam Support is a tell in itself.

There is no urgent need to reset a Steam password, since credentials were not part of this incident, though a strong unique password and Steam Guard two-factor authentication remain worth having. The practical defense is refusing to act on inbound messages about a delivery: go to the retailer or carrier's own site instead of following a link.

Context

Valve's own systems have been breached before, in 2011, when records for 35 million users including usernames, email addresses and encrypted credit card details were exposed. A more recent claim, a threat actor offering what looked like 89 million Steam user records for sale in May 2025, turned out to be old SMS messages carrying expired two-factor codes, routed through a third party Valve says it never partnered with. This time the company was not the one breached, which is the recurring shape of these incidents: personal data leaves through a supplier, as it did when a breach at Hyundai Turkey exposed job applicants' test results. Customers still receive the consequences.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions