SYS::ONLINE
Wasteland.
Briefs1888
Issues23
SinceFeb 2026
LIVE
▣ Breach VALVE-CEVA-LOGISTI 2026-08-12

Valve: Supply Chain Breach at CEVA Logistics Exposes European Steam Hardware Buyers

"Valve has begun emailing European customers who bought Steam hardware to tell them their delivery data was likely stolen in a cyberattack on CEVA Logistics, the contractor that ships Steam Deck, Steam Machine and Steam…"

Valve has begun emailing European customers who bought Steam hardware to tell them their delivery data was likely stolen in a cyberattack on CEVA Logistics, the contractor that ships Steam Deck, Steam Machine and Steam Controller units across the continent. Valve's notification, republished by recipients on Reddit and seen independently by The Register and Infosecurity Magazine, dates the intrusion to July 29 through August 1, 2026, and says Valve itself only learned on August 7 that Steam customer records were caught up in it. CEVA, a subsidiary of French shipping group CMA CGM with more than 1,000 warehouses worldwide and $18.3 billion in 2025 revenue, has confirmed that its European contract logistics operations were hit and that eight warehouses were affected. No party has published a victim count, and the exposure is not limited to Valve: Dutch retailer Bol, department store De Bijenkorf, football club Ajax and banking group ING have all been named as affected CEVA clients.

What Happened

The timeline is consistent across sources on the intrusion window itself. Valve's customer email, quoted by Neowin, Cybernews, The Register and DayOne, places the attack between July 29 and August 1, 2026. FreightWaves, cited by both TechCrunch and The Register, reports the hack began on July 29 and is still causing shipping delays in the affected warehouses.

Accounts differ on when CEVA told its clients. The statement CEVA provided to Infosecurity Magazine says the company "notified impacted customers on August 1." Valve's own notification, and TNW's reporting citing CNET, both put the moment Valve learned of the Steam data exposure at August 7. The most likely reading is that CEVA issued an initial operational notice on August 1 and only confirmed the data theft on August 7, but neither company has said so explicitly, and the six-day gap is unexplained in the public record.

CEVA has drawn a tight perimeter around the incident. Its statement to Infosecurity says the breach touched its European contract logistics arm, which handles warehousing, fulfilment, manufacturing support and aftermarket services, and adds that "no other Ceva systems globally were affected, and all other operations continue without incident." The Register reports that CEVA's air, ocean, ground and rail transportation businesses ran normally throughout. Per Cybernews and DayOne, CEVA has isolated and taken the affected system offline and brought in an outside investigation team.

The blast radius outside Valve is where this stops being a gaming story. TechCrunch, which broke the multi-client angle, reports that several companies relying on CEVA for last-mile delivery have told their own customers that personal data was taken. Bol said on its website that attackers reached the systems of its warehousing partner and warned of delays and cancelled orders; Infosecurity adds that restoration at CEVA's Veerweg site is taking longer than expected. De Bijenkorf, Ajax and ING appear on the affected-client list in both TechCrunch and Infosecurity reporting.

What Was Taken

Valve's notification is unusually specific about the exposed fields, and the list is corroborated across The Register, DayOne, Cybernews and TNW:

TNW notes that BleepingComputer likewise reported product type and price paid as part of the set, matching The Register's independent reading of the email.

Equally specific is what CEVA never held. Valve says payment information, Steam passwords and Steam Guard codes were not exposed because CEVA has no access to them, a point repeated in every source covering the notification. Valve is explicit that customers do not need to change passwords or alter account settings.

No record count has been published by anyone. CEVA has not disclosed scope, Valve has not stated how many customers it emailed, and no outlet in this reporting set offers a figure. The only bound available is CEVA's 90-day retention window for delivery data, which Valve says is why it wrote to everyone it could reasonably assume was affected. In practice that means roughly three months of European Steam hardware orders, a population Valve cannot precisely enumerate either.

One source overstates the scope. eTeknix writes that "all European Steam users have received a message," which conflicts with Valve's own wording and with every other account. The notification went to hardware purchasers inside the retention window, not the general Steam userbase.

Why It Matters

This is a textbook third-party data incident: the attacker never touched Valve, Bol, ING or Ajax, and yet all four are notifying customers. The data lives with the fulfilment contractor because it has to, and the contractor's retention policy, not the brand's, determines the size of the exposure. Valve appears aware of the optics. Neowin observes that Valve's email does not read as an endorsement of its partner's handling of the incident.

The stolen field set is close to optimal for social engineering. A scammer holding a name, verified home address, phone number, the exact email tied to the target's Steam account and the specific model and price of hardware that is genuinely in transit can construct a delivery-fee lure that survives every instinctive plausibility check a recipient applies. TNW puts its finger on the sharpest detail: the order email is the Steam account email, so the attacker knows precisely which inbox matters for any follow-on account-takeover attempt.

TechCrunch also flags the strategic reason logistics keeps getting hit. Beyond data, access to shipping and warehouse systems lets criminals reroute or hijack physical goods, putting cargo theft crews and network intruders in the same operation. Data exfiltration may be the visible half of an intrusion whose commercial motive was freight.

The Attack Technique

Nothing published so far identifies an initial access vector, a malware family or a threat actor. No group has claimed the breach in any of these sources, no ransom demand has been reported, and neither CEVA nor Valve has characterised the intrusion beyond calling it a cyberattack.

What can be said from the evidence: the attacker held access for roughly four days, reached systems spanning at least eight European warehouses across multiple unrelated client accounts, and exfiltrated fulfilment records rather than payment or authentication data. That pattern is consistent with access to a shared warehouse management or fulfilment platform serving many clients from common infrastructure, which would explain how a single intrusion produced simultaneous notifications from a games company, two Dutch retailers, a football club and a bank. Treat that as inference, not confirmation. CEVA's investigation is ongoing, and Valve says it is still working with CEVA to establish "the full scope of what was taken and how" while notifying data protection authorities in the affected countries.

What Organizations Should Do

  1. Inventory which third parties hold your customer PII, and what their retention clock is. CEVA's 90-day window defined the victim population here. If you cannot state a fulfilment or logistics partner's retention period from memory, you cannot scope your own exposure when they get breached.
  2. Contract for breach notification timelines, in hours, not best effort. The public record shows a gap between CEVA's August 1 client notice and Valve's August 7 confirmation of data theft. Every day in that gap is a day your customers are phishable and you are silent.
  3. Pre-write the supply chain breach notification template now. Valve's email works because it names the exact fields taken, states plainly what was not taken, tells customers they need take no account action, and describes the specific scams to expect. Draft that structure before you need it.
  4. Brief support and fraud teams on delivery-themed pretexting. Expect inbound from customers who received messages quoting real addresses and real order details. Frontline staff need to know the breach is real, the data is accurate, and the messages still are not from you.
  5. Harden the channels attackers will impersonate. Valve's guidance is worth copying: support handles issues only on the official help page, never by email, chat or Discord, and neither support nor a courier ever asks for a password or a one-time code. Publish your equivalent and make it easy to find.
  6. Watch for follow-on account takeover, not just fraud. Because order emails frequently match account emails, monitor for credential stuffing, password reset attempts and unusual login geography against the notified cohort, even where no credentials were exposed.

Sources: Valve informs customers about data breach, personal data stolen - N... | A data breach at shipping giant Ceva Logistics is rippling ... | Logistics Giant Ceva Suffers Data Breach Impacting ... | Cyberattack on logistics giant CEVA delivers customer data into the... | Steam hardware customer data in Europe exposed in logistics company... | European Steam Hardware Customers Hit by Cyber Attack DayOne | Steam Indirectly Hit by Data Leak, Users Warned to Watch Out for Sc... | Valve is warning Steam Machine buyers that scammers ...