Valve has warned European customers who purchased Steam hardware that some personal information may have been compromised following a data breach. The incident affected European buyers of the Steam Machine hardware.

The breach occurred at Valve's logistics partner, CEVA Logistics, between July 29 and August 1. Valve stated that it learned about the cyberattack at CEVA Logistics on August 7.

The compromised data is limited to standard delivery information shared with CEVA Logistics for shipping purposes. This includes names, addresses, phone numbers, email addresses, and order details.

According to Valve, payment information, account security keys, and Steam account credentials were not affected by the breach, as CEVA Logistics did not have access to financial data or account security keys.


Valve warned that the leaked email addresses and phone numbers could expose users to direct targeting and fraud attempts via fraudulent emails, texts, or phone calls.

Valve said these fake messages may appear to come from Steam, Valve, or a delivery company. Such messages might ask recipients to pay a small customs or redelivery fee or to sign into a service to verify an order.

Affected users do not have to change their Steam passwords or account details.


Valve is currently working with CEVA Logistics to determine exactly what data was stolen and is pressing the partner for the full scope of the incident and how it occurred.

The company has notified European data protection authorities about the breach and is in the process of notifying authorities in the specific countries affected.

The breach was first reported by Engadget.