Valve told European Steam hardware customers on September 16, 2026 that a cyberattack on its shipping partner, CEVA Logistics, did not reach the systems that processed their orders. The message closed out a six-week saga that started with an alarming August notice and ended, for now, with a quieter one. In between, at least six named companies across banking, retail, sports, and gaming confirmed they were caught up in the same breach, and ten organizations reported incidents to Dutch data protection authorities tied to the same attacker.
The story matters beyond Steam Deck owners in Amsterdam or Berlin. CEVA Logistics is a subsidiary of the French shipping giant CMA CGM, and it moved roughly 15 million shipments in 2025 through more than 1,000 warehouses worldwide, according to figures reported by TechCrunch. When a vendor that size gets hit, the fallout does not stay contained to one client. Valve just happened to be the client whose customers pay the most attention to security news.
What Valve Told Steam Hardware Customers on September 16
The September 16 email was a follow-up, not a first alert. Valve had already warned affected buyers in August. This second message, reported first by GamingOnLinux and later covered by PC Guide, walked back some of the anxiety from the original notice. Valve wrote that “the attack was limited to a subset of their systems” and that “the system that processed your Steam hardware order was not affected.” The company added there was “currently no indication that your data was accessible to the attacker at any time during this incident.”
Valve also apologized for the six-week gap between the first warning and this clarification, telling customers it was sorry “for the delay while this was confirmed and apologize for any confusion or alarm that resulted from our prior notification.” That is an unusually direct admission for a company that rarely comments on its own security posture in public.
Reaction on Steam’s own community forums, captured by GamingOnLinux, split roughly into three camps. Some users said the original email had frightened them badly enough that the walk-back felt like relief. Others pointed out, reasonably, that no company can promise total safety from a third-party breach it does not control. A smaller group noted they never received either email and guessed CEVA’s coverage varies by country, since the carrier does not ship every Steam hardware order across every European market.
Inside the CEVA Logistics Cyberattack Timeline
Piecing together the public record from Valve’s own emails and reporting by BleepingComputer and TechCrunch, the attack ran from July 29 to August 1, 2026. CEVA discovered the intrusion around August 1 and isolated the affected systems. Valve says it learned of the likely compromise on August 7, six days before it sent its first customer notice on August 10. The September 16 update arrived five weeks after that first notice, once CEVA had gathered enough detail to narrow the scope.
That gap between discovery and full clarity is fairly ordinary for supply chain incidents involving a logistics partner rather than a company’s own network. CEVA does not answer to Valve’s security team, so Valve was dependent on CEVA’s own investigators for updates it could pass along. CEVA said in its own statement, reported by TechCrunch, that “as soon as the incident was identified, CEVA’s cybersecurity teams immediately activated its security protocols and launched a thorough investigation.”
| Date | Event | Source |
|---|---|---|
| July 29 – August 1, 2026 | Attackers active inside a subset of CEVA Logistics systems | Valve customer email, cited by BleepingComputer |
| August 1, 2026 | CEVA identifies the intrusion and isolates affected systems | TechCrunch |
| August 7, 2026 | Valve learns Steam-related delivery data was likely exposed | Valve customer email |
| August 10, 2026 | Valve sends first breach notification to affected European buyers | BleepingComputer, TechCrunch |
| Mid-August 2026 | Dutch data protection authority receives breach reports from 10 organizations tied to the CEVA incident | TechCrunch |
| September 16, 2026 | Valve sends a follow-up email narrowing the impact and confirming order-processing systems were untouched | GamingOnLinux, PC Guide |
What Data Was Exposed, and What Was Not
Valve’s original notice described a narrow but real category of exposure. CEVA holds delivery information for Steam hardware orders, not account data. According to the August email, cited by both BleepingComputer and TechCrunch, the fields that may have been compromised included a customer’s name, street address, postal code, city, country, phone number, the email address tied to their Steam account, and the type and price of the hardware ordered.
Valve was equally specific about what CEVA never had. The company stressed that payment details, Steam passwords, Steam Guard two-factor codes, and other account credentials sit entirely outside CEVA’s systems and were not touched. That distinction is the reason this incident reads as serious but contained rather than catastrophic. A stolen shipping address is a real privacy and phishing risk. A stolen Steam password is a wallet-draining emergency. This breach, as far as the public record shows, is the former.
Valve used its September follow-up to warn customers about the most likely abuse of the leaked data: convincing phishing attempts. The company told buyers that scammers “may quote your address back to you to prove they’re genuine” in follow-up scam emails or calls, and instructed customers to “treat all of them as fake” regardless of how accurate the personal details sound. That is sound advice, and it echoes guidance security teams gave after similar logistics breaches at retailers in prior years.
CEVA Logistics: The Company Behind Steam’s European Shipping
Most Steam Deck owners had never heard of CEVA Logistics before this month. The France-headquartered firm is a subsidiary of CMA CGM, one of the world’s largest container shipping groups, and it handles fulfillment for a long list of retailers well outside gaming. TechCrunch put CEVA’s 2025 revenue at $18.3 billion and its footprint at more than 1,000 warehouses globally, of which only eight in Europe were confirmed touched by this particular attack.
That scale is the whole story here. A logistics company that large sits behind dozens of consumer brands that never appear on its own website. Customers of those brands rarely know CEVA exists until something goes wrong, at which point they discover their address book, phone number, and purchase history passed through a vendor they never agreed to trust directly. Valve’s own statement made clear it does not control CEVA’s internal security, only its own contract with the carrier, which is a normal but limiting arrangement in retail logistics.
Six Named Companies, Ten Reported Incidents
Valve was not CEVA’s only exposed client. TechCrunch’s August reporting named Bol, the large Dutch online retailer, along with De Bijenkorf, a Dutch luxury department store chain, Ajax, the Amsterdam football club, ING, the Dutch banking group, and Ace & Tate, an eyewear retailer, as companies whose customer data moved through the same compromised CEVA systems. Ten separate organizations filed breach reports with the Dutch data protection authority in connection with the incident, though not every affected company has been named publicly.
| Company | Sector | Region | Data Reportedly Exposed |
|---|---|---|---|
| Valve (Steam hardware) | Gaming / consumer electronics | Europe-wide | Name, address, phone, email, order type/price |
| Bol | E-commerce retail | Netherlands | Delivery and contact details |
| De Bijenkorf | Department store retail | Netherlands | Delivery and contact details |
| Ajax | Sports / football club | Netherlands | Delivery and contact details |
| ING | Banking | Netherlands | Delivery and contact details |
| Ace & Tate | Eyewear retail | Netherlands | Delivery and contact details |
The pattern across that list is instructive. None of these companies compete with each other, and none of them share a product category with Valve. What they share is a delivery contract with the same logistics vendor. That is the defining feature of a supply chain breach: the attacker does not need to know or care what a given client sells, only that the client’s shipping data sits on a system worth breaching once.
The GDPR Angle: Why Dutch Regulators Got Involved
Under the EU’s General Data Protection Regulation, a company that experiences a personal data breach affecting EU residents generally has 72 hours to notify the relevant supervisory authority once it becomes aware of the incident, per Article 33 of the regulation. Valve told customers it was “notifying the data protection authorities in the countries affected, including yours,” language that signals the company is treating this as a reportable breach rather than a minor technical hiccup.
The involvement of the Dutch data protection authority specifically ties back to CEVA’s exposed clients being heavily concentrated in the Netherlands, given Bol, De Bijenkorf, Ajax, ING, and Ace & Tate are all Dutch companies. Regulators in other affected countries may still be reviewing their own notifications quietly, since GDPR breach reports are not automatically made public unless a regulator chooses to disclose them or a fine eventually follows.
How This Compares to Past Gaming Industry Breaches
Gaming companies have a long, uncomfortable history with security incidents, but most of the well-known ones look nothing like the CEVA case. In September 2022, Rockstar Games suffered a direct intrusion into its internal development network that leaked early Grand Theft Auto VI footage and source code, an attack traced to a hacker linked to the Lapsus$ group who compromised Rockstar’s own systems rather than a vendor’s. Electronic Arts disclosed in mid-2021 that attackers had stolen game source code and internal tools, including material tied to its Frostbite engine, after buying stolen session cookies on a criminal forum and walking directly into EA’s Slack. CD Projekt Red was hit by ransomware in February 2021 that encrypted internal systems and led to the theft of source code for Cyberpunk 2077 and The Witcher 3.
All three of those incidents involved attackers reaching a game studio’s own infrastructure. The CEVA breach is different in kind. Valve’s internal Steam systems, its account database, and its payment processing were never in the blast radius, based on everything disclosed so far. The exposure sits one layer removed, inside a fulfillment partner that Valve trusted with names and addresses so it could ship hardware. That distinction is exactly why this story reads as less severe than a Rockstar-style intrusion, even though it hit a wider mix of unrelated companies at once.
Competitive Comparison: How Other Platforms Handle Hardware Fulfillment Risk
Valve is not the only platform holder shipping physical hardware through third parties. Sony, Microsoft, and Nintendo all rely on regional logistics contractors to move consoles, controllers, and accessories, and none of the big three has published a breach notice this year tied to a fulfillment partner. That does not mean their vendor risk is lower, only that it has not surfaced publicly, or that their contracts route less identifying data through carrier systems in the first place.
The structural difference worth noting is that Steam Deck, Steam Machine, and Steam Controller sales run through Valve’s own storefront rather than third-party retail chains for a large share of European buyers, which means CEVA held a concentrated pool of Steam-linked delivery data in one place. Nintendo, Sony, and Microsoft hardware, by contrast, sells heavily through retail partners like Amazon, MediaMarkt, and Currys, spreading delivery data across many more logistics relationships and making any single vendor breach proportionally smaller for those platforms.
| Platform | Primary EU Fulfillment Model | 2026 Vendor Breach Disclosed | Data Concentration Risk |
|---|---|---|---|
| Valve (Steam hardware) | Direct-to-consumer via Steam store, regional carriers | Yes, CEVA Logistics | Higher, single carrier for many direct orders |
| Sony (PlayStation hardware) | Mostly retail partners plus direct store | None disclosed in 2026 | Lower, spread across many retailers |
| Microsoft (Xbox hardware) | Mostly retail partners plus direct store | None disclosed in 2026 | Lower, spread across many retailers |
| Nintendo (Switch 2 hardware) | Mostly retail partners plus direct store | None disclosed in 2026 | Lower, spread across many retailers |
Why Gaming Companies Keep Getting Hit Through Suppliers
Supply chain risk has become the quiet theme of gaming security coverage over the past two years, running alongside the more headline-grabbing direct intrusions. A studio can lock down its own network, enforce multi-factor authentication, and still get exposed the moment a shipping partner, a payment processor, or a customer support vendor gets breached. CEVA’s incident fits a wider pattern in 2026 in which attackers increasingly target the mid-size vendors that sit quietly behind consumer brands, precisely because those vendors often carry weaker security budgets than the household names they serve.
The economics explain why this keeps happening. Breaching Valve directly means going up against a company that has spent two decades hardening Steam against fraud and account theft. Breaching CEVA means going up against a logistics contractor whose core competency is warehousing and shipping, not cybersecurity, yet whose systems still hold the same personal data attackers want. From an attacker’s perspective, the vendor is the softer target with a comparable payoff.
Market Impact for Valve and the Steam Hardware Business
The timing is awkward for Valve’s hardware ambitions. Steam Deck and related hardware pricing has already been under pressure from the broader memory chip shortage squeezing PC and console makers through 2026, and a security story, even a contained one, adds friction right as Valve wants European buyers focused on its hardware lineup rather than its vendor security. There is no evidence in current reporting that the breach has slowed hardware sales, and Valve’s quick reassurance email appears designed specifically to prevent that kind of reputational drag before it starts.
Longer term, incidents like this tend to push platform holders toward tighter data-sharing agreements with logistics vendors, sometimes limiting what fields a carrier is allowed to retain and for how long. Valve’s own emails referenced CEVA’s data retention window as the basis for estimating which customers were affected, which suggests Valve is already thinking about how long a vendor should be allowed to hold delivery records after a package ships.
Historical Context: Logistics as the New Weak Link
Retail and shipping vendors have been a recurring soft target for years outside gaming too, and the CEVA case slots into that longer history rather than starting a new one. Large-scale breaches at retail-adjacent processors have repeatedly shown that a single compromised vendor can expose customers of a dozen unrelated brands at once, because the vendor sits in the middle of many separate customer relationships simultaneously. What is new in 2026 is how directly that pattern has now touched a major gaming platform’s own hardware business, rather than just a publisher’s marketing vendor or a payment gateway.
What Steam Hardware Buyers in Europe Should Do Now
Valve’s own guidance is a reasonable starting point. Anyone who bought Steam hardware and shipped it within Europe during the relevant window should assume their name, address, phone number, and Steam-linked email could be in circulation, and should treat unsolicited emails, texts, or calls referencing that order with suspicion, even if the sender appears to know accurate personal details. Steam account credentials were not part of this exposure, so there is no need to reset a Steam password purely because of this incident, though enabling Steam Guard two-factor authentication remains good practice regardless.
Customers who never received either Valve email but are unsure whether they were affected can contact Steam Support directly, which is the channel Valve pointed customers toward in its September message. Anyone who receives a follow-up message referencing their Steam order should independently verify it through Steam’s official support channels rather than clicking links or calling numbers provided in the unsolicited message itself.
Five Predictions for What Happens Next
- Expect at least one more update from Valve once CEVA’s full internal investigation formally closes, likely including a firmer count of affected customers by country.
- Dutch and other EU data protection authorities will probably take months to conclude their reviews, and any fine against CEVA, if one comes, is unlikely to surface before 2027 given typical GDPR enforcement timelines.
- Other CEVA clients beyond the six named so far may confirm their own exposure as more national regulators process breach reports tied to the same root incident.
- Valve and other hardware-selling platforms will likely tighten contractual limits on how much customer data logistics vendors can retain and for how long, following the same pattern seen after past retail vendor breaches.
- Phishing attempts referencing real Steam hardware order details will likely tick up over the next few months, and Steam Support will probably field a wave of reports asking whether specific messages are genuine.
The Bigger Picture for Steam Deck’s Reputation
Steam Deck has spent the past few years building a reputation as the reliable, community-trusted option in a handheld market crowded with competitors. A vendor breach does not undo that reputation on its own, especially one where account security was never at risk and Valve communicated clearly, if slowly, about what happened. But it is a reminder that trust in a platform extends past the platform’s own code to every vendor that touches a customer’s data along the way, from the payment processor to the warehouse that puts a Steam Deck box on a delivery van.
Frequently Asked Questions
Was my Steam account password stolen in the CEVA Logistics breach?
No. Valve has stated that CEVA Logistics never had access to Steam account credentials, passwords, or Steam Guard codes. The exposure was limited to delivery-related information such as name, address, phone number, and order details.
What is CEVA Logistics and why does it have my data?
CEVA Logistics is a France-headquartered shipping and warehousing company owned by CMA CGM. Valve uses CEVA to fulfill and deliver Steam hardware orders, such as the Steam Deck, Steam Machine, and Steam Controller, to customers across Europe.
When did the CEVA Logistics attack actually happen?
According to Valve’s customer notifications, the attack occurred between July 29 and August 1, 2026. CEVA identified the intrusion around August 1, and Valve says it learned of the likely data exposure on August 7, 2026.
Which other companies were affected by the same breach?
TechCrunch reported that Bol, De Bijenkorf, Ajax, ING, and Ace & Tate, all based in the Netherlands, were among the companies whose customer data moved through the same compromised CEVA systems. Ten organizations in total reported related incidents to the Dutch data protection authority.
Do I need to do anything after receiving Valve’s September email?
Valve’s guidance is to remain alert for phishing messages that reference your real order details, since scammers may use leaked delivery information to appear credible. There is no indication that a password reset or payment card cancellation is necessary specifically because of this incident.
Is this breach covered under GDPR?
Yes. Valve has said it is notifying data protection authorities in the affected countries, consistent with the EU’s GDPR breach notification requirements under Article 33, which generally require reporting a personal data breach to a supervisory authority without undue delay.
Has Valve confirmed exactly how many customers were affected?
No specific customer count has been made public. Valve has said it estimated the affected group using CEVA’s data retention window rather than providing an exact figure, and reporting so far describes the scope in terms of warehouses (eight in Europe) rather than individual customers.
How does this compare to past breaches at game companies like Rockstar or EA?
It is a different category of incident. The Rockstar Games leak in 2022 and the EA breach in 2021 both involved attackers reaching the companies’ own internal development systems. The CEVA breach never touched Valve’s internal Steam infrastructure. It was limited to a third-party shipping vendor’s systems.




