Cyber Incident Victim: Valve Corporation
Timeline
Summary
Valve warned Steam Machine and Steam Controller customers that their personal data may have been stolen after a cyberattack on its European shipping partner Ceva Logistics compromised names, addresses, countries, phone numbers, Steam email addresses and hardware purchase details while payment information and passwords remained secure. The company reported that the intrusion affected eight warehouses in Europe, causing shipping delays and prompting investigations by Dutch authorities, and advised recipients to treat any unsolicited messages referencing their orders as fraudulent.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Ceva Logistics began experiencing a cyber intrusion on July 29, which affected at least eight of its warehouses across Europe. The company confirmed the breach to affected customers on August 1, stating that its cybersecurity teams had activated security protocols and launched an ongoing investigation, while noting that the operational impact was limited to those eight warehouses and that no other CEVA systems globally were compromised. Valve learned on August 7 that data had been taken from CEVA’s systems and subsequently informed customers who had recently purchased Steam hardware that their personal information had been involved in the incident, noting that CEVA retains shipping and delivery information for 90 days after an order.

The data exfiltrated from CEVA included customers’ names, home addresses, countries, phone numbers, Steam email addresses, and details of Steam hardware purchases; payment information and passwords were not leaked according to Valve’s communication. Other organizations that rely on CEVA for logistics also reported impacts, including Dutch retailer Bol, luxury retailer De Bijenkorf, football club Ajax, banking giant ING, and eyeglass maker Ace & Tape, citing order delays and potential data exposure. CEVA’s website was not loading properly at the time of the initial reports, and the company said some affected applications and services had been restored while it continued to work with authorities. The Dutch data protection authority indicated it had received breach reports from ten organizations linked to the CEVA incident.
In response, CEVA activated its security protocols, began a thorough investigation, and collaborated with law enforcement, though a spokesperson declined to disclose the volume of data taken or whether any ransom demand had been received. Valve issued a warning to Steam Machine and Steam Controller customers that their personal data may have been stolen due to the CEVA breach and clarified that the compromised data did not include payment credentials or passwords. The company also reminded customers that CEVA stores shipping and delivery information for a 90‑day window following a purchase. No further details about the attackers’ identity or motives were provided in the available sources.
