Valve has notified customers of a data breach affecting those who ordered Steam hardware in Europe. The company’s logistics partner, CEVA Logistics, experienced unauthorized access to customer information between July 29th and August 1st. Personal details potentially compromised include names, addresses, phone numbers, and email addresses associated with orders for Steam devices.
The breach occurred shortly after Valve began accepting pre-orders for its new Steam Machine and Steam Controller. CEVA Logistics retains delivery-related customer data for up to 90 days following orders, making European customers vulnerable during the breach window. Valve has confirmed that the exposure was limited to shipping information and does not extend to payment details, passwords, or Steam Guard security codes.
In response to the incident, Valve is warning customers to remain vigilant against fraudulent communications. The company expects customers may receive deceptive emails, text messages, or phone calls impersonating Steam, Valve, or delivery services. These scams may reference customer addresses to appear legitimate and could request payment for customs fees or ask users to verify orders through fake portals.
Valve clarified that it handles account issues exclusively through its official support website at help.steampowered.com and will not contact users via email, Steam chat, or Discord. Customers are advised to treat any unsolicited communications claiming to be from Steam or affiliated companies as potentially fraudulent.
