stadiongaming.eu

Valve warns Europe: Steam hardware buyers caught in a logistics data leak

A breach at CEVA Logistics exposed names, addresses, phone numbers and order details of Steam Machine and Steam Controller buyers across Europe. No passwords or payment data - which is exactly what makes the scam texts that follow so convincing.

Jakov Mikelić

Tuesday, August 11, 2026

Valve warns Europe: Steam hardware buyers caught in a logistics data leak

Anyone in our region who has ordered hardware from abroad in the last couple of years knows the routine. A text lands saying your parcel is being held, there's a small fee to settle, here's the link. You roll your eyes, delete it, move on. From this week, a lot of Steam hardware buyers across Europe should think twice - because the person sending that message may genuinely know what they ordered and what they paid for it.

Valve has notified Steam Machine and Steam Controller customers in Europe that CEVA Logistics, the partner that moves its hardware around the continent, was breached. Valve's own servers weren't touched. The intrusion is reported to have happened around the turn of the month, and Valve says it was informed on 7 August that customer data had likely been accessed.

What's in the pile: full name, street address, postal code, city and country, phone number, the email address tied to the Steam account, and the type and price of the hardware ordered. What isn't in it: Steam passwords, Steam Guard codes, payment details, and anything about your other purchases. Valve was clear on that, and it matters - nobody is draining your card with this data directly.

Why "just shipping data" is the worst kind of boring leak

The reason I'm not shrugging at this one is that last field. Type and price of the hardware ordered. A generic phishing message that guesses you're waiting for a package works maybe one time in a hundred. A message that greets you by name, quotes your street, and mentions the exact device you're waiting on and roughly what it cost - that one gets clicked. Valve itself is telling people to expect fake emails, texts and calls pretending to be Steam, Valve or a courier, typically asking you to confirm a delivery, pay a small customs or redelivery charge, or log in somewhere to "verify" the order.

That last variant is the dangerous one. Nothing here compromises your account on its own, but a convincing login page plus a rushed user can finish the job that the leak started. And people ordering a Steam Machine are, by definition, people with a Steam library worth stealing.

Worth noting too that Valve is far from the only victim. Reporting has tied the same CEVA incident to a bank, a football club and a retailer, which tells you something uncomfortable about how much of Europe's parcel flow runs through a handful of logistics firms. You can pick your storefront. You don't get to pick who carries the box.

Practical version, and it's short. Nothing you buy from Valve will ever require a follow-up payment by text message. Courier fee messages with a payment link are a scam by default - and within the EU there is no customs charge on an intra-EU shipment anyway, no matter how official the message looks. If you get anything that smells like Steam support, don't use the link: open the Steam client or type the address yourself. And if you've been putting off the mobile authenticator, now is a genuinely good week to stop putting it off.

The irony is that the hardware itself is still the slow part of this story. People here have been waiting months for these devices, and the first message they get about their order may well be a fake one.

Image: Liam Dawe/GamingOnLinux, PNG version by VulcanSphere / CC BY-SA 4.0, source: https://commons.wikimedia.org/wiki/File:Steam_Deck_(front).png