Breach analysis · 5 min read

Steam Hardware Buyers Caught in the CEVA Logistics Breach

A cyberattack on Valve's European shipping partner exposed the names, addresses and emails of Steam hardware buyers. What leaked, and what to do.

YeyMail Team ·

If you bought a Steam Deck, Steam Machine or Steam Controller in Europe this summer, there may be an email from Valve in your inbox, and it is genuine. On 10 August 2026 the company began notifying customers that their delivery details had been exposed in a cyberattack. The weak point was not Steam itself but CEVA Logistics, the shipping firm that handles Valve's hardware deliveries across Europe.

The Steam notices are one strand of a much wider incident. According to TechCrunch, the intrusion at CEVA began on 29 July 2026 and affected at least eight of the company's European warehouses, with consequences reaching a Dutch bank, several retailers and a football club as well as Valve.

No passwords or payment details were taken. But what did leak, a real name, a home address, a phone number and the email address tied to a Steam account, is precisely the raw material of a convincing fake-delivery or phishing message. Here is what has been verified so far, how to check whether you are affected, and what to do if you are.

What happened, and when

CEVA Logistics is a subsidiary of the French shipping group CMA CGM, and by BleepingComputer's account it runs roughly 1,000 warehouses worldwide and handled 15 million shipments in 2025. Valve is one of many companies that contract it for fulfilment; when you order Steam hardware in Europe, CEVA is the firm that warehouses and ships it.

The timeline is unusually precise. According to BleepingComputer, the attackers had access to CEVA's systems between 29 July and 1 August 2026. CEVA confirmed a cyber intrusion affecting part of its European contract logistics operations, isolated the compromised systems and brought in external investigators. Valve says it was informed on 7 August and began emailing affected customers on 10 August, three days later.

Valve is far from the only client caught up. TechCrunch reported that the Dutch online retailer Bol, the department store De Bijenkorf, the eyewear brand Ace & Tate, the football club Ajax and the bank ING all had customer shipping data exposed in the same incident, and that the Dutch data protection authority has received breach reports from ten organisations connected to it.

What data leaked

For Steam hardware customers, the exposed fields are the ones a shipping company holds by necessity. According to BleepingComputer, drawing on Valve's notification, the stolen data includes names, home addresses, phone numbers, email addresses and the type and price of the hardware ordered.

The scope has a natural limit. Both TechCrunch and BleepingComputer note that CEVA retains shipping and delivery information for 90 days, so the exposure covers recent European hardware orders rather than every Steam hardware buyer.

Just as important is what was not taken. Steam passwords, Steam Guard codes, payment card details and account information were not exposed, because CEVA never had them; a logistics partner sees the parcel, not the account. Valve told affected customers that they "do not need to change your Steam password". Neither Valve nor CEVA has published a total count of affected people, and no overall victim figure has been disclosed, so treat any precise number you see elsewhere with caution.

How to check whether you are affected

Valve says it has emailed every customer it believes was affected, so the first check is your own inbox, including the spam folder, for a notice sent on or after 10 August. Be careful here: a breach notification is itself a favourite disguise for phishing. The genuine notice tells you what happened; it does not ask you to log in, confirm your details or click through to a payment page. If in doubt, open Steam directly rather than following any link.

Beyond that, Have I Been Pwned is the standard way to see what your address has already been caught up in. There is no guarantee this particular dataset will ever be added, but checking costs nothing, and the results are worth understanding properly; we have written a guide to reading Have I Been Pwned results and acting on them.

If you are affected

There is no password to change and no card to cancel, which makes this breach feel deceptively mild. The real risk arrives later, as emails, text messages and phone calls that know your name, your address and exactly what you ordered. A message about a customs charge on your Steam Machine, or a failed delivery of your Steam Controller, will look plausible because it is built from real order data.

  • Treat any message that references your Steam hardware order with suspicion, however accurate its details. Go to the retailer's or courier's site directly instead of clicking links.
  • Never pay a "customs" or "redelivery" fee requested by email or text message.
  • Expect the scams to be slow as well as fast. Leaked datasets circulate for years, so an approach next spring is as likely as one next week.
  • Work through our full checklist for what to do when your email leaks rather than improvising.

The pattern this breach repeats

The people affected made no mistake. They bought hardware from a company they trusted, and that company passed their details, quite legitimately, to a contractor most of them had never heard of. This is the defining shape of the modern breach: not the service you signed up to, but a supplier one or two steps removed. Every online order scatters your details across a retailer, a payment processor, a courier and often a marketing platform, and you cannot assess the security of firms you cannot name. It is also why working out who leaked your address after the fact is usually guesswork.

There is one genuinely encouraging detail. CEVA's 90-day retention window meant the attackers could only take three months of orders, not a decade of them. Data minimisation is usually discussed as an abstraction; here it visibly shrank the damage. The lesson cuts the other way for the identifier at the centre of it all: your postal address changes when you move and your phone number can be replaced, but most people carry one email address across every shop, courier and platform for years. Every leak that includes it links back to the same inbox, which is why the spam that follows a breach is so hard to shake off.

The YeyMail takeaway
One address per shop limits the blast radius

YeyMail gives every retailer its own email alias, so the address sitting in a logistics database would be one you created for that shop and used nowhere else. When it leaks, you know exactly which supply chain leaked it, and the kill switch lets you shut that one address down: mail to it is refused at SMTP time with "no such address", nothing queued or filtered. The switch is never paywalled and keeps working even after you cancel. Your real inbox stays out of the dataset entirely. Plans start at $0.99 a month, and there is a free 7-day trial with no card required.

Start free — one alias per signup7-day trial · No credit card

Sources

Common questions

Was my Steam password or payment card exposed in the CEVA breach?

No. According to Valve's notification, passwords, Steam Guard codes and payment details were not affected, because CEVA never had access to them. The exposed data is limited to shipping details: name, address, phone number, email address and the hardware ordered.

How do I know if I am affected?

Valve says it emailed every customer it believes was affected, starting on 10 August 2026. Only European Steam hardware orders within CEVA's 90-day retention window are in scope. If you have no notice from Valve and have not ordered hardware recently, you are unlikely to be included.

Do I need to change my Steam password?

Valve says no, and there is no technical reason to. No credentials were exposed in this incident. Enabling Steam Guard is still sensible as general practice, but this breach does not put your account itself at risk.

What scams should I watch for after this breach?

Fake delivery notices, customs-fee demands and Steam support impersonations, all made convincing by real order details. Never pay a fee or enter credentials from a link in an unexpected message; go to the site directly instead. Leaked data circulates for years, so stay wary well beyond the next few weeks.

Which other companies were affected by the CEVA Logistics breach?

TechCrunch reported that the Dutch retailer Bol, the department store De Bijenkorf, the eyewear brand Ace & Tate, the football club Ajax and the bank ING also had customer shipping data exposed, and that ten organisations have filed breach reports with the Dutch data protection authority.

Will this breach show up on Have I Been Pwned?

There is no guarantee; not every stolen dataset becomes public or gets loaded into the service. It is still worth checking your address there for earlier breaches, but Valve's direct email remains the authoritative way to know whether this incident includes you.

Keep reading

Breach response
Your Email Was Leaked: The Complete What-Now Checklist
Breach response
Have I Been Pwned: How It Works and What Results Mean
Privacy guide
How to Find Out Which Company Leaked Your Email