breaking news

Steam has contacted consumers after a cyber attack at a partner business left the personal details of many compromised.
An email has been issued to affected consumers within Europe pertaining only to those who may have ordered hardware, including items like the Steam Machine and Steam Controller.
CEVA Logistics, the company charged with shipping Steam hardware within Europe on behalf of Valve, is what has been hit by a cyber attack.
The attack took place between July 29 2026, and August 1 2026, but Valve notes that it only learned of the attack on August 7.
Advert
“Certain information about Steam customers, including you, was likely compromised,” an email said to users, as shared by Reddit user nelsonflagship.
“CEVA received specific delivery-related information from Steam to be able to shop physical hardware to customers in Europe, and told us these are the details the attacker likely took,” the email continued.
“Because CEVA retains this information for up to 90 days after that order, we are sending this message to all customers we can assume were impacted.”
Steam goes on to detail the precise information it expects is lost to the attacker:
- Name
- Street address, postal code, and city
- Country
- Phone number
- Email address - “the same one your Steam account uses”
- The type and price of the ordered product
Steam goes on to note that no other information pertaining to Steam accounts - like passwords- was lost, nor were any other purchases impacted.
CEVA does not store payment information, so this was also kept safe alongside Steam Guard codes.
How do I know if I’m affected?
Again, this cyber attack pertains only to those who ordered hardware from Steam/Valve within the last couple of months in the region of Europe.
Other territories were not affected, and handily, Steam appears to have issued emails to all those it expects were affected, so it’s worth checking your emails.
What should I do if my details are compromised?
As passwords were not lost, none of your personal accounts should have been hacked, but it’s perhaps always safer to ensure two-factor authentication is turned on.
The most important thing users can now do is look out for suspicious activity.
The lost information may be used to email or text affected users, with the attacker hiding under the guise of being Steam/Valve.
If you do receive anything of that nature, perhaps luring you in with fake compensation or asking you to ‘verify’ orders, be wary.
Make sure that you only engage with communications from Steam and Valve’s official noted channels and email addresses.
Users are, understandably, concerned following the email rolling out.
“Whelp. Spam call protection will have to work overtime,” said Msasti.
“Just got this myself… I’ve actually lost count of how many times my data has been involved in a data breach like this,” Lo_jak added.
“The only way they can make it up to me is by moving from the waitlist to reserve now, just saying,” added an angered Content_Composer_671, hoping to nab more hardware.
It’s a worrying time for affected users, but all key advice is contained within the email from Steam.