CSIDB logo
Incident

Valve Corporation

Incident posture

Attack window
Jul 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-31 20:14

Linked entities

Victim
Valve Corporation
Threat actors
0 actors
Sources
9 sources

Timeline

Occurred
Jul 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending

Summary

Valve reported that a cyberattack on its European logistics partner CEVA Logistics exposed personal information of customers who purchased Steam hardware, including names, addresses, phone numbers, email addresses and order details, while payment data remained secure. The breach disrupted operations at eight of CEVA’s European warehouses, leading to order delays and cancellations for some customers. The company notified affected individuals, warned them of possible phishing attempts using the stolen data, and said it was working with the partner and authorities to investigate the incident.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 29 2026 attackers gained access to systems operated by CEVA Logistics, a subsidiary of the CMA CGM Group, and the intrusion persisted through August 1, affecting eight of the company’s European warehouses that handle contract logistics for multiple clients. CEVA confirmed the cyber intrusion on August 1, stating that the operational impact was limited to those eight warehouses while all other global operations continued without incident. On August 7 CEVA informed Valve, the U.S. video game company behind the Steam platform, that its European contract logistics systems had been compromised and that delivery‑related information for Steam hardware orders might have been accessed. Valve said it learned on that date that data had been taken from CEVA’s systems and that it could not determine precisely which records were obtained, prompting it to notify customers whose information it could reasonably assume may have been affected. The notification was sent to European customers who had recently purchased Steam hardware such as Steam Machines or Steam Controllers, with Valve explaining that CEVA retains delivery‑related data for up to 90 days after an order. According to Valve’s disclosure, the potentially exposed information included customers’ names, street addresses, postal codes, cities, countries, telephone numbers, email addresses, and details about the type and price of the Steam hardware they ordered, while payment information, passwords, and Steam Guard codes remained secure because CEVA does not handle those data types.

The breach disrupted CEVA’s European warehouse operations, leading to shipping delays and, in some cases, order cancellations for Valve’s Steam hardware customers, as reported by both Valve and affected retailers such as Bol and De Bijenkorf. Valve warned recipients that the exposed personal details could be used in phishing or scam attempts, advising them to expect fraudulent emails, SMS messages, or phone calls that reference their hardware order and appear to come from Steam, Valve, or a delivery company, and to treat any such communication as fake. The company emphasized that Steam’s support team never contacts users via email, Steam chat, Discord, or third‑party services and would never ask for passwords or Steam Guard codes. In addition to the customer notification, Valve stated that it was pressing CEVA for a full scope of the data that had been taken and was in the process of informing data‑protection authorities in the countries affected by the incident.

CEVA responded by activating its security protocols, launching an ongoing investigation, and working with authorities; the company reported that some of its affected applications and services had been restored to online status. CEVA’s spokesperson declined to provide further details on the volume of data taken or any communication from the attackers, including possible ransom demands. Dutch data‑protection authorities confirmed they had received breach reports from at least ten organizations linked to the CEVA incident, and they were investigating the attack alongside national law‑enforcement agencies. No public attribution of the attack has been made, and it remains unclear whether ransomware was deployed or whether an extortion demand was issued. The incident concluded with Valve’s customer alerts, its warnings about follow‑up scams, and its continued coordination with CEVA and regulatory bodies to address the breach’s aftermath.

Sources

Sources available to members: 9 sources.

CSIDB