Valve is notifying European Steam customers that their personal shipping information was exposed following a data breach at its logistics partner, CEVA Logistics, between July 29 and August 1, 2026.
Key Points
- Valve confirmed that its own internal systems were not compromised, as the breach occurred exclusively within the infrastructure of its shipping partner, CEVA Logistics.
- Exposed data includes customer names, physical addresses, telephone numbers, and specific hardware order details.
- CEVA Logistics, a subsidiary of the CMA CGM Group, manages global supply-chain operations and reported $18.3 billion in revenue for 2025.
- Security experts warn that the stolen information provides a foundation for highly targeted phishing and delivery-themed social engineering scams.
- Affected users are advised to avoid clicking links in unsolicited delivery notifications and to verify order status directly through official retailer websites.