Steam is emailing UK customers to warn their details may have been stolen
Key Points
- Valve is emailing UK Steam customers whose hardware delivery details were likely stolen in a cyberattack on courier CEVA Logistics between 29 July and 1 August 2026.
- Exposed data covers name, full address, phone number, email address, and the product type and price ordered.
- Payment details, passwords and Steam Guard codes were not held by CEVA and are unaffected, and Valve says no password change is needed.
- The main risk is targeted phishing by email, SMS or phone from scammers who can quote a real address and order back to the customer.
- Dutch retailers Bol and De Bijenkorf have issued similar warnings over the same breach.
Steam is emailing UK customers to warn their delivery details may have been stolen.
Valve has started emailing UK Steam customers to tell them their delivery details were likely stolen in a cyberattack on the courier that ships its hardware across Europe.
A copy of the notification seen by HotMinute names CEVA Logistics as the company involved and dates the attack to between 29 July and 1 August 2026.
Valve said it learned on 7 August that customer information was likely compromised, and is writing to everyone it can reasonably assume was caught up in it. CEVA holds the delivery data for up to 90 days after an order.
The email lists the information at risk as the customer’s name, street address, postal code and city, country, phone number, email address, and the type and price of the product ordered.
Valve said nothing else tied to the Steam account or to other purchases was affected, and that CEVA never held payment details, passwords or Steam Guard codes. The company tells recipients they do not need to change their Steam password or alter any account settings.
CEVA is one of the largest third-party logistics providers in the world, with more than 1,000 warehouses globally.
Freight trade title FreightWaves reported that operations at eight of its European warehouses were disrupted over the weekend of 1 August, causing shipping delays for retail clients storing inventory at those sites, and that affected corporate customers were notified on 1 August.
The Dutch Data Protection Authority and other law enforcement agencies are investigating.
Dutch retailers Bol and De Bijenkorf have already warned their own shoppers.
Bol said its systems were untouched but that names, addresses, phone numbers, email addresses and order information may have been viewed or copied, while payment details and passwords were not.
It pulled part of its product range from sale at the affected site and paused data sharing with the logistics partner.
Public import records place CEVA at the centre of Valve’s European hardware distribution. Shipments arriving from China in May 2026 were addressed to “CEVA NL c/o Valve Corporation” and logged as game consoles, according to import data reported by Notebookcheck.
Valve confirmed in June that the Steam Machine and Steam Frame would ship over the summer, adding a fresh wave of European hardware orders to the Steam Deck deliveries already flowing through the same route.
Scam risk
Valve’s warning centres on fraud rather than account security.
Anyone holding the stolen records knows the customer’s name, home address, phone number, email address and the exact product and price of a recent order, which is enough to build a convincing fake message about a delivery.
The email tells customers to expect scam contact by email, SMS and phone that appears to come from Steam, Valve or a courier, and that may quote a home address back as proof of legitimacy.
Typical approaches include confirming a delivery, paying a small customs or redelivery fee, or signing in somewhere to verify an order.
The notification repeats three points about how Steam operates. Steam Support handles account issues only through help.steampowered.com, never by email, Steam Chat or Discord.
Genuine Steam login pages sit on store.steampowered.com, www.steampowered.com, steamcommunity.com or help.steampowered.com, and Valve advises typing those addresses manually rather than following a link.
Neither Steam Support nor a courier will ever ask for a password or a Steam Guard code.
Valve said it is pressing CEVA for the full scope of the theft and is notifying data protection authorities in the affected countries, which for UK customers means the Information Commissioner’s Office.
CEVA has isolated and taken the affected systems offline and brought in outside investigators. Valve has designated ARTANA Digital GmbH in Hamburg, an external data protection firm, as its contact point for further information about the incident.
Neither company had commented publicly on the incident at the time of publication.