Valve has notified European customers that their personal information may have been exposed following a data breach at CEVA Logistics, the company’s European shipping partner. The breach, which occurred between July 29th and August 1st, 2026, may have compromised customer names, addresses, phone numbers, and email addresses.
Valve disclosed the incident via email to affected users, explaining that CEVA stores “delivery-related information” for up to 90 days after orders are fulfilled. The company confirmed that European customer data “was likely compromised” as part of the breach. The timing follows weeks after Valve began taking reservations for its new Steam Machine and Steam Controller.
Valve was quick to clarify the limits of the exposure. CEVA does not have access to payment information, passwords, Steam Guard codes, or other Steam account data, and Valve says that information linked to users’ Steam accounts or purchases was not impacted.
The company is urging affected customers to be on alert for phishing attempts. Valve warned users to “expect fake messages” arriving via email, text, or phone that claim to be from Steam, Valve, or a delivery company. According to Valve, these messages may reference a customer’s address to appear legitimate and could request actions such as confirming a delivery, paying a customs or redelivery fee, or signing in to “verify” an order. Valve’s guidance is direct: “Treat all of them as fake.”
Valve also reminded customers that it only handles account issues through help.steampowered.com and will not contact users via email, Steam chat, or Discord. Customers who receive suspicious messages should disregard them entirely rather than engage.
Source: The Verge