
Steam Hardware Delivery Data Breach: What Customers Should Know
Valve says a cyberattack at European shipping partner CEVA Logistics likely exposed contact, delivery and product-order details for some Steam hardware customers.
The short version
What you need to know
- Valve says attackers accessed CEVA Logistics systems between 29 July and 1 August, and that some European Steam hardware delivery information was likely compromised.
- The likely exposed fields include names, addresses, phone numbers, email addresses, product types and prices; Valve says payment data, Steam passwords and Steam Guard codes were not available to CEVA.
- The main customer risk is a convincing delivery, customs or account-verification scam. A VPN cannot recover exposed shipping records or make a message trustworthy.
What happened?
BleepingComputer reported on 10 August that Valve is notifying European customers after a cyberattack affected CEVA Logistics, the company that ships Steam hardware in Europe. According to the notice quoted by the publication, attackers accessed CEVA systems from 29 July through 1 August, and Valve learned on 7 August that Steam customer information was likely compromised.
CEVA reportedly keeps delivery information for up to 90 days after an order. Valve is therefore contacting the customers it can reasonably assume were affected rather than claiming that every European Steam account or every Steam purchase was exposed.
What information was likely exposed?
Valve says the delivery data supplied to CEVA can include a customer's name, physical address, phone number, email address, product ordered and product price. Those details can reveal that a person recently bought Steam hardware and give a scammer enough context to imitate Valve or a courier.
The same notice says CEVA does not receive Steam passwords, Steam Guard codes, payment information or details of unrelated Steam purchases. Valve says customers do not need to change their Steam password or account settings specifically because of this incident. That does not rule out phishing attempts designed to steal those credentials later.
What customers should do now
Treat unexpected messages about a delivery, customs charge, redelivery fee or account verification as suspicious even when they quote your real name, address or order. Open Steam through the official app or type the official address yourself rather than following a link in an email, text or search advert.
Do not provide a password, Steam Guard code or card number to an unsolicited caller or message. If you entered credentials on a suspicious page, change the password through Steam's official route, review authorised devices and sessions, and contact Steam Support. Report fraudulent card activity to the card issuer and keep the original message as evidence.
Where a VPN helps — and where it does not
A reputable VPN can encrypt traffic between your device and the VPN server on an untrusted local network and hide your usual public IP address from many websites. That is useful for network privacy, including when checking an account while travelling.
A VPN cannot remove delivery records already held by a logistics company, tell whether an email or text is genuine, block every fake checkout page or recover money sent to a scammer. This breach calls for careful message verification, strong account security and prompt fraud reporting—not simply a different IP address.
VPN Rocks view
The absence of passwords and payment details narrows the immediate impact, but accurate order and address data can make social engineering unusually persuasive. Customers should distrust the request, not the level of personal detail used to support it.
Retailers should also minimise how long delivery partners retain customer fields and make breach notices specific about what the supplier could access. Clear boundaries help people take proportionate action without unnecessary password resets or panic.
Primary reading
Sources and further reading
We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.
