PSA: Steam Machine and Steam Controller Customers in Europe Hit by Cyber Attack

Valve has notified European customers who purchased Steam hardware that their personal data was likely compromised in a cyberattack targeting CEVA Logistics, the company responsible for shipping Steam products across Europe. The attack occurred between July 29 and August 1, 2026, though Valve only learned of the breach on August 7.

The compromised data includes customer names, addresses, phone numbers, countries of residence, Steam account email addresses, and Steam hardware purchase details. Importantly, Valve has confirmed that passwords and payment information were not exposed in the breach.

The incident affects any European customer who ordered Steam hardware—including the newly released Steam Machine and Steam Controller, as well as the Steam Deck—within approximately the past 90 days, coinciding with how long CEVA retains delivery information.

Valve is warning affected customers to expect phishing attempts via email, SMS, or phone calls from scammers posing as Valve or delivery companies. The company notes that fraudsters may reference customers’ addresses to appear legitimate. Customers are advised to remain vigilant and not respond to unsolicited communications claiming to relate to their hardware orders.

This breach represents a significant privacy incident for Valve’s European user base, though the exposure of non-financial data somewhat limits the immediate financial risk to customers.

Sources