Valve is warning Steam Machine buyers that scammers have their address

Nothing was taken from Steam. The names, addresses and phone numbers went out of the company that puts the box on the van.


Valve is warning Steam Machine buyers that scammers have their address

Valve has emailed European customers who ordered a Steam Machine or a Steam Controller. A cyberattack on CEVA Logistics, the firm that ships Valve hardware across Europe, took their delivery details.

CNET’s Tyler Graham reported the warning on Monday. CEVA told Valve about the breach on 7 August, and Valve spent the following days working out who to contact.

A Valve spokesperson told CNET that CEVA is still investigating. The company decided to write to everyone it could reasonably assume was affected, based on what it knows now.

Valve makes hardware as well as running the store. The Steam Machine and the Steam Controller follow the Steam Deck, and it moves all of them into Europe through a logistics contractor.

What went, and what did not

The exposed data covers names, countries, street addresses, phone numbers and email addresses. BleepingComputer adds the product type and the price paid to that list.

One line in the notice does more work than the rest. The email address on the order is the same one the Steam account uses, so a scammer now knows the exact inbox that matters.

Payment details, passwords and Steam Guard codes are not on it. Valve says CEVA never had access to them.

Valve also says the shipping information sat with CEVA for 90 days after each order. That window decides who got caught.

The warning is the useful part

Valve’s email tells customers to expect fake messages about their order, and recipients have posted it on Reddit. Those may arrive by email, text or phone, and may appear to come from Steam, Valve or a courier.

Then it makes the point that matters. The messages may quote the customer’s own address back to them to prove they are genuine, and they may ask for a small customs or redelivery fee.

“Treat all of them as fake,” the email says.

Valve adds that Steam support handles problems only on its official help page, never over email, Steam chat or Discord. Its staff never ask for a password or a Steam Guard code. Neither, the email notes, will a courier.

The accounts themselves need no action. Nobody has to change a Steam password or touch their settings, because the breach never reached either.

Eight warehouses and a widening list

TechCrunch’s Zack Whittaker traced the attack back to 29 July. Valve’s notice dates the intrusion between then and 1 August. CEVA confirmed it that day, six days before it told Valve.

Valve is one name on a longer list. Whittaker names the Dutch retailers Bol and De Bijenkorf, the bank ING, the eyewear firm Ace & Tate and the football club Ajax.

The logistics side has its own damage. FreightWaves reported disruption at eight European warehouses, with orders, returns and refunds all running late.

Bol and De Bijenkorf suspended data exchanges with CEVA as a precaution, according to Eric Kulisch’s reporting. Products at the affected sites went offline.

The supplier is the surface

CEVA is not a small vendor. It runs more than 1,000 warehouses, handles roughly 15 million shipments a year and reported $18.3bn of revenue in 2025, as a subsidiary of the shipping group CMA CGM.

That scale is the point. One intrusion at a contract logistics provider reaches a games company, a bank and a football club in the same week, which is what people mean by a digital supply chain.

The pattern is familiar. LastPass customers lost data through a supplier rather than through LastPass.

Polymarket users lost funds the same way. That was a third-party breach of much the same shape.

What nobody knows yet

The count is missing. Neither Valve nor CEVA has said how many customers are affected, how much data left, or how the attackers got in.

Attribution is missing too. No group has claimed the intrusion, and nothing published so far names one.

CEVA has said little. It told TechCrunch the incident touched part of its European contract logistics operations, and that other operations continue without incident.

Valve fills in a little more. It says CEVA has isolated the affected systems, pulled them offline and brought in outside investigators, and that Valve is still pressing the contractor for the full scope.

The regulators come next. Valve is notifying the data protection authority in every affected country, and it has named Artana Digital GmbH in Hamburg as its contact point for questions about the incident.

The Dutch regulator is already investigating. Dutch police took down 800 servers in a separate operation earlier this year.

Everything else is a wait. The people who ordered a Steam Machine now have a home address sitting in someone else’s file, and the only defence Valve can offer is the instruction to disbelieve the next convincing message about their parcel.

Get the TNW newsletter

Get the most important tech news in your inbox each week.