PC gamers waiting for Steam hardware may soon face a scam that knows what they bought, where it is going, and how much it costs. Valve is warning some European customers after a cyberattack at CEVA Logistics, a shipping partner that handled their deliveries.
The exposed information could make phishing attempts look unusually convincing. Attackers may know a customer’s name, address, phone number, email, product, and order price, giving them enough detail to impersonate Steam, Valve, or a delivery company.
Valve says the incident did not expose Steam passwords, Steam Guard codes, payment card information, or unrelated Steam purchases. The main risk is targeted social engineering, where accurate delivery details are used to pressure customers into clicking links, sharing credentials, or paying fraudulent fees.
What happened with the shipping partner
CEVA Logistics said a cyber intrusion affected part of its European contract logistics operation between July 29 and August 1, 2026. The incident disrupted operations at at least eight European warehouses while cybersecurity teams isolated affected systems and investigated the intrusion.
Valve said it learned on August 7 that information connected with some European Steam hardware customers was likely compromised. It then began notifying customers whose delivery records could have been stored within CEVA systems during the relevant period.
CEVA can retain delivery information for up to 90 days after an order, so customers can receive warnings even when their hardware arrived weeks earlier. The available reports do not establish the attack vector, the perpetrators, the ransom status, or the final number of affected records.
Which customer information may be exposed?
Valve’s notification identifies information needed to complete hardware deliveries. Potentially exposed details include names, street addresses, postal codes, cities, countries, phone numbers, email addresses, hardware types, and order prices.
Those details can become powerful ingredients for a personalized scam. A criminal who knows someone ordered a Steam Controller could mention the product directly and then claim the shipment is delayed because the address requires confirmation.
The product price adds credibility. A message referencing a real $99 controller or a more expensive Steam Machine could make a customs charge, redelivery fee, or payment request appear connected to a genuine order.
Why this phishing threat is different
This is not the typical spam message that arrives without context. A scammer can use legitimate delivery information to build a believable story, making a fake notification feel familiar before the recipient has any reason to question it.
A message could claim that delivery is blocked, customs payment is overdue, or an address must be verified. The victim might then be directed to a fake Steam login page or payment portal designed to collect sensitive information.
Valve has warned that criminals may quote a recipient’s address to prove a contact is authentic. That makes the breach particularly concerning because correct personal details are normally a useful clue, but here they may have been stolen.
Little-known fact: CEVA breach also compromised customer data at other major clients, including the Dutch retailer Bol, the department store De Bijenkorf, the eyewear brand Ace & Tate, and the Amsterdam football club Ajax.
Could your Steam account be hacked?
Valve says customers do not need to change Steam passwords or alter account settings solely because of this shipping incident. The compromised information came from CEVA’s delivery systems rather than Steam’s account or payment infrastructure.
That distinction is important because exposed data can enable impersonation without granting attackers direct access to a Steam account. A scammer still needs the victim to provide credentials, authentication codes, payment information, or other data.
Little-known fact: Steam has more than 130 million registered accounts, making it a lucrative target for hijacking attempts even without a direct password leak.

How scammers could use real orders
The most convincing attacks may arrive through email, text, or phone calls. The criminal can pose as Steam, Valve, CEVA, or another courier and use genuine order information to sound legitimate.
The attacker may create a sense of urgency by claiming a package cannot be delivered without a small payment. Other variations could request address confirmation, customs charges, identity information, or a one-time code before releasing the hardware.
If the victim follows the supplied link, a counterfeit website could request a Steam password, Steam Guard code, card details, or personal information. Those details could then enable account theft, financial fraud, or additional attacks against other accounts.
Little-known fact: Fake package-delivery alerts were the single most-reported text scam of 2024, contributing to $470 million in FTC-reported losses, five times 2020’s total.
Steam Machine orders may draw attention
The incident arrives as Valve expands its hardware ambitions. The Steam Machine is a compact SteamOS gaming PC designed for living rooms, giving buyers a console-like experience while retaining access to the broader PC gaming ecosystem.
Reported specifications include a six-core, 12-thread AMD Zen 4 processor, an AMD RDNA 3 graphics processor with 8GB of GDDR6 memory, 16GB of DDR5 system memory, and 512GB or 2TB solid-state storage.
Valve also describes living-room features, including Wi-Fi 6E, Bluetooth, gigabit Ethernet, DisplayPort 1.4, HDMI 2.0, and a 300-watt internal power supply. The system measures roughly six inches in each dimension and runs SteamOS.
The new Steam Controller adds interest
The redesigned Steam Controller is another product linked to Valve’s current hardware push. It uses two haptic trackpads, TMR thumbsticks, four assignable grip buttons, a six-axis gyroscope, and capacitive grip sensing for a broad range of control options.
The controller supports multiple connections, while Valve’s wireless puck can connect up to four controllers and integrates with the Steam Machine. Reported battery life reaches 35 hours or more, giving scammers another product to reference.
Reported pricing puts the Steam Machine around $1,049 for 512GB and $1,349 for 2TB, while the Steam Controller costs about $99 separately. Regional pricing varies, but accurate product and price information could make fraudulent messages seem especially credible.
How should affected gamers respond?
Customers should treat unexpected Steam or delivery messages as suspicious, even when they include correct names, addresses, order details, or shipping information. Accuracy alone is no longer a reliable sign that a delivery notification is legitimate.
Do not click links in unexpected messages or call phone numbers in suspicious emails or texts. Instead, open Steam or Valve support independently through a known bookmark, the official client, or a manually entered support address.
Delivery status should also be checked through a courier’s independently verified website or app. Customers should never provide Steam passwords, Steam Guard codes, payment information, or one-time authentication codes to someone who contacted them first.
What this breach means beyond Steam
The incident highlights why logistics companies can be attractive targets even when they do not hold account passwords or payment cards. Shipping records can link a person’s identity, phone number, email address, home address, product, and delivery timeframe.
That combination can support follow-on attacks against email accounts, courier accounts, smart-home services, or other household members. For smart-home users, leaked delivery data can also reveal which technology products are arriving at a particular home.
CEVA operates more than 1,000 warehouses globally and reported approximately $18.3 billion in revenue in 2025. CEVA said the operational impact was limited to eight European warehouses, while the wider data-access scope remained under investigation.

TL;DR
- European Steam hardware customers may face targeted phishing because leaked delivery records can contain accurate names, addresses, contact details, products, and prices.
- Valve says Steam passwords, Steam Guard codes, payment cards, and unrelated Steam purchases were not exposed through the CEVA shipping incident.
- Scammers may impersonate Valve or couriers, using real order details to request fake customs fees, address confirmations, credentials, or authentication codes.
- Customers should independently verify deliveries and avoid links, phone numbers, payment requests, or authentication demands contained in unexpected messages.
This article was made with AI assistance and human editing.
If you liked this, you might also like:
Trending Products
iRobot Roomba Plus 405 (G181) 2in1 ...
Tipdiy Robot Vacuum and Mop Combo,4...
iRobot Roomba 104 2in1 Vacuum &...
Tikom Robot Vacuum and Mop Cleaner ...
ILIFE Robot Vacuum
T2280+T2108
ILIFE V5s Pro Robot Vacuum and Mop ...
T2353111-T2126121
Lefant Robot Vacuum Cleaner M210, W...
