A Steam data breach at shipping partner CEVA leaked hardware buyers’ names, home addresses, and phone numbers, giving scammers plenty of real information to work with.
Anyone who spent months waiting on a Steam Machine or controller just got an extra headache nobody signed up for. Valve is emailing Steam customers after CEVA Logistics, the company handling Steam hardware shipments across Europe, was hit by attackers between July 29 and August 1.
Your box may have arrived just fine, but some of the delivery information attached to it ended up somewhere it shouldn’t.
- The Breach: Steam itself wasn’t breached. CEVA was, and the information exposed is much more useful for believable phishing attempts than immediately stealing money from your account.
- What Was Leaked: Names, street addresses, phone numbers, emails, and detailed order information, including what customers paid, were likely exposed. Passwords, payment information, and Steam Guard codes weren’t.
- What it Means: The bigger risk isn’t someone logging into your Steam account right away. It’s getting a convincing message later from somebody who already knows your name, address, and what you ordered.
The Weak Link Was the Shipping Company, Not Valve

Valve’s own systems weren’t breached, and the company got warning emails out quickly. Once those customer details are exposed, though, it doesn’t really matter which company in the delivery chain lost control of them.
Your Password Survived, and That’s Cold Comfort
Passwords, payment details, and Steam Guard codes weren’t part of the breach, so this doesn’t give somebody what they need to simply log into your Steam account, fortunately.
The rest of the leaked details make phishing messages harder to spot, though, becasue a fake delivery notice gets much more convincing when the sender already knows your real address and exactly what Steam hardware you ordered.
Fake Delivery Notices Are About to Flood In
Either way, if your information was caught up in the CEVA breach, expect bogus emails, texts, and phone calls pretending to come from Steam, Valve, or the courier. Watch for customs-fee scams asking for a small payment to release a package, fake redelivery notices, and password-reset messages pushing you toward a login page.
Don’t click links in unexpected messages. Steam Support won’t ask you for your password or Steam Guard code, and neither will a courier. Be especially suspicious when a message starts pushing urgency and telling you something has to be handled immediately.
Final Thoughts on the Steam Data Breach
Steam wasn’t hacked here. CEVA was, but customers still end up dealing with the fallout because personal information has to move through several companies before hardware reaches your door.
The breach has already happened, so now the practical risk is what somebody tries to do with the information. Watch incoming emails, texts, and calls closely, especially anything tied to deliveries or account access.
Scammers still need you to click the link or hand over the login, and the good news is that’s the part you can still control.
Did you get one of Valve’s breach warning emails, and are the sketchy messages starting to roll in yet?


