7 min read
PC gamers waiting for Steam hardware may soon face a scam that knows what they bought, where it is going, and how much it costs. Valve is warning some European customers after a cyberattack at CEVA Logistics, a shipping partner that handled their deliveries.
The exposed information could make phishing attempts look unusually convincing. Attackers may know a customer’s name, address, phone number, email, product, and order price, giving them enough detail to impersonate Steam, Valve, or a delivery company.
Valve says the incident did not expose Steam passwords, Steam Guard codes, payment card information, or unrelated Steam purchases. The main risk is targeted social engineering, where accurate delivery details are used to pressure customers into clicking links, sharing credentials, or paying fraudulent fees.
CEVA Logistics said a cyber intrusion affected part of its European contract logistics operation between July 29 and August 1, 2026. The incident disrupted operations at at least eight European warehouses while cybersecurity teams isolated affected systems and investigated the intrusion.
Valve said it learned on August 7 that information connected with some European Steam hardware customers was likely compromised. It then began notifying customers whose delivery records could have been stored within CEVA systems during the relevant period.
CEVA can retain delivery information for up to 90 days after an order, so customers can receive warnings even when their hardware arrived weeks earlier. The available reports do not establish the attack vector, the perpetrators, the ransom status, or the final number of affected records.

Valve’s notification identifies information needed to complete hardware deliveries. Potentially exposed details include names, street addresses, postal codes, cities, countries, phone numbers, email addresses, hardware types, and order prices.
Those details can become powerful ingredients for a personalized scam. A criminal who knows someone ordered a Steam Controller could mention the product directly and then claim the shipment is delayed because the address requires confirmation.
The product price adds credibility. A message referencing a real $99 controller or a more expensive Steam Machine could make a customs charge, redelivery fee, or payment request appear connected to a genuine order.
This is not the typical spam message that arrives without context. A scammer can use legitimate delivery information to build a believable story, making a fake notification feel familiar before the recipient has any reason to question it.
A message could claim that delivery is blocked, customs payment is overdue, or an address must be verified. The victim might then be directed to a fake Steam login page or payment portal designed to collect sensitive information.
Valve has warned that criminals may quote a recipient’s address to prove a contact is authentic. That makes the breach particularly concerning because correct personal details are normally a useful clue, but here they may have been stolen.
Little-known fact: CEVA breach also compromised customer data at other major clients, including the Dutch retailer Bol, the department store De Bijenkorf, the eyewear brand Ace & Tate, and the Amsterdam football club Ajax.
Valve says customers do not need to change Steam passwords or alter account settings solely because of this shipping incident. The compromised information came from CEVA’s delivery systems rather than Steam’s account or payment infrastructure.
That distinction is important because exposed data can enable impersonation without granting attackers direct access to a Steam account. A scammer still needs the victim to provide credentials, authentication codes, payment information, or other data.
Little-known fact: Steam has more than 130 million registered accounts, making it a lucrative target for hijacking attempts even without a direct password leak.

The most convincing attacks may arrive through email, text, or phone calls. The criminal can pose as Steam, Valve, CEVA, or another courier and use genuine order information to sound legitimate.
The attacker may create a sense of urgency by claiming a package cannot be delivered without a small payment. Other variations could request address confirmation, customs charges, identity information, or a one-time code before releasing the hardware.
If the victim follows the supplied link, a counterfeit website could request a Steam password, Steam Guard code, card details, or personal information. Those details could then enable account theft, financial fraud, or additional attacks against other accounts.
Little-known fact: Fake package-delivery alerts were the single most-reported text scam of 2024, contributing to $470 million in FTC-reported losses, five times 2020’s total.
The incident arrives as Valve expands its hardware ambitions. The Steam Machine is a compact SteamOS gaming PC designed for living rooms, giving buyers a console-like experience while retaining access to the broader PC gaming ecosystem.
Reported specifications include a six-core, 12-thread AMD Zen 4 processor, an AMD RDNA 3 graphics processor with 8GB of GDDR6 memory, 16GB of DDR5 system memory, and 512GB or 2TB solid-state storage.
Valve also describes living-room features, including Wi-Fi 6E, Bluetooth, gigabit Ethernet, DisplayPort 1.4, HDMI 2.0, and a 300-watt internal power supply. The system measures roughly six inches in each dimension and runs SteamOS.
The redesigned Steam Controller is another product linked to Valve’s current hardware push. It uses two haptic trackpads, TMR thumbsticks, four assignable grip buttons, a six-axis gyroscope, and capacitive grip sensing for a broad range of control options.
The controller supports multiple connections, while Valve’s wireless puck can connect up to four controllers and integrates with the Steam Machine. Reported battery life reaches 35 hours or more, giving scammers another product to reference.
Reported pricing puts the Steam Machine around $1,049 for 512GB and $1,349 for 2TB, while the Steam Controller costs about $99 separately. Regional pricing varies, but accurate product and price information could make fraudulent messages seem especially credible.
Customers should treat unexpected Steam or delivery messages as suspicious, even when they include correct names, addresses, order details, or shipping information. Accuracy alone is no longer a reliable sign that a delivery notification is legitimate.
Do not click links in unexpected messages or call phone numbers in suspicious emails or texts. Instead, open Steam or Valve support independently through a known bookmark, the official client, or a manually entered support address.
Delivery status should also be checked through a courier’s independently verified website or app. Customers should never provide Steam passwords, Steam Guard codes, payment information, or one-time authentication codes to someone who contacted them first.
The incident highlights why logistics companies can be attractive targets even when they do not hold account passwords or payment cards. Shipping records can link a person’s identity, phone number, email address, home address, product, and delivery timeframe.
That combination can support follow-on attacks against email accounts, courier accounts, smart-home services, or other household members. For smart-home users, leaked delivery data can also reveal which technology products are arriving at a particular home.
CEVA operates more than 1,000 warehouses globally and reported approximately $18.3 billion in revenue in 2025. CEVA said the operational impact was limited to eight European warehouses, while the wider data-access scope remained under investigation.

This article was made with AI assistance and human editing.
If you liked this, you might also like:
We appreciate you taking the time to share your feedback about this page with us.
Whether it's praise for something good, or ideas to improve something that
isn't quite right, we're excited to hear from you.
Lucky you! This thread is empty,
which means you've got dibs on the first comment.
Go for it!