Valve has notified European customers who bought Steam hardware that personal delivery and order data was likely stolen after a cyberattack on shipping partner CEVA Logistics. The company said attackers had access to CEVA servers between July 29 and August 1, 2026, exposing names, addresses, phone numbers, email addresses, and the type and price of ordered products tied to Steam hardware shipments, including older purchases such as Steam Machines and Steam Controllers.
Valve said the breach was limited to fulfillment data held by CEVA and did not expose Steam account credentials, payment card information, or Steam Guard codes. The company warned affected customers to expect phishing emails, text messages, and phone calls impersonating Valve, Steam, or delivery firms, including scams requesting customs or delivery fees or login details. CEVA said it isolated affected systems, notified data protection authorities, and brought in external investigators after the attack also disrupted operations at eight European warehouses.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Valve said it is notifying data protection authorities in affected countries following the CEVA Logistics breach affecting European Steam hardware customer data. The statement accompanied Valve's customer notifications about the likely exposure of shipping and order information.
Valve began notifying affected Steam hardware customers in Europe about the CEVA Logistics breach and warned them to expect phishing emails, texts, or calls impersonating Steam, Valve, or delivery firms. Valve also said no Steam account credentials, payment information, or Steam Guard codes were exposed.
Valve said it learned on August 7, 2026 that attackers had stolen information tied to European Steam hardware orders handled by CEVA Logistics. The exposed data likely included names, addresses, phone numbers, email addresses, and product type and price.
Bol said the Dutch Data Protection Authority was informed on August 3, 2026 about the possible customer data leak tied to the cyberattack on CEVA Logistics. The notification followed CEVA's August 1 alert to Bol and preceded customer emails sent after further investigation.
IT Pro reported that Levi Strauss was among the organizations believed to be affected by the CEVA Logistics breach, alongside previously disclosed customers such as ING, Bol, De Bijenkorf, Ajax, and Ace & Tate. This expands the known set of CEVA customers impacted by the incident.
Reporting on the CEVA Logistics cyberattack said the compromised data also included personal data belonging to CEVA employees and contract workers, in addition to customer contact and order details. This expanded the known impact beyond previously disclosed downstream customer shipping data.
Multiple organizations, including Bol, De Bijenkorf, Ajax, ING, and Ace & Tate, reported that customer shipping information held by CEVA Logistics was affected by the incident. Some also disclosed operational fallout such as order delays and cancellations tied to the disruption at CEVA's European warehouses.
Ten organizations filed data breach notifications with the Dutch Data Protection Authority in connection with the CEVA Logistics incident. This expands the known regulatory response beyond previously disclosed individual notifications such as Bol's report.
The Dutch Data Protection Authority and other law enforcement agencies were reported to be investigating the CEVA Logistics cyber incident affecting eight European warehouses. The investigation was disclosed alongside retailer notices describing operational disruption and possible exposure of customer shipping data.
CEVA Logistics informed multiple European retailers that a cyberattack had disrupted operations at eight of its warehouses in Europe. This disclosure was reported as occurring on August 1, 2026.
Valve said attackers had access to CEVA Logistics servers during a cyberattack affecting its European hardware distribution operations. The intrusion window was stated as July 29, 2026 through August 1, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
25 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecyberveille.ch
Open sourcesecurityaffairs.com
Open sourcesecurityweek.com
Open sourcenos.nl
Open sourcefreightwaves.com
Open sourcenos.nl
Open sourcedebijenkorf.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.