AUTO-UPDATED

Steam customers caught in supply-chain breach as hackers target logistics partner

Valve is notifying European Steam customers that their personal shipping information was exposed following a data breach at its logistics partner, CEVA Logistics, between July 29 and August 1, 2026.

Key Points

  • Valve confirmed that its own internal systems were not compromised, as the breach occurred exclusively within the infrastructure of its shipping partner, CEVA Logistics.
  • Exposed data includes customer names, physical addresses, telephone numbers, and specific hardware order details.
  • CEVA Logistics, a subsidiary of the CMA CGM Group, manages global supply-chain operations and reported $18.3 billion in revenue for 2025.
  • Security experts warn that the stolen information provides a foundation for highly targeted phishing and delivery-themed social engineering scams.
  • Affected users are advised to avoid clicking links in unsolicited delivery notifications and to verify order status directly through official retailer websites.

Why it Matters

This incident highlights the growing vulnerability of modern businesses to supply-chain attacks, where hackers target third-party vendors to bypass robust internal security measures. It serves as a critical reminder that an organization's data security is only as strong as the weakest link in its network of external partners.
Digital Journal Published by Dr. Tim Sandle
Read original