READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

CEVA Logistics Breach Exposes Steam Hardware Buyers' Names and Addresses in Europe

CEVA Logistics Breach Exposes Steam Hardware Buyers' Names and Addresses in Europe
A cyberattack on shipping giant CEVA Logistics between July 29 and August 1 exposed customer names, addresses, phone numbers, and emails, including data on Europeans who ordered Valve's new Steam Machine and Steam Controller. Valve says payment info, passwords, and Steam Guard codes are safe, but warns customers to expect scam calls and texts. This one breach at a single logistics company is now rippling across banks, retailers, and a soccer club.

Valve is warning European customers who ordered its upcoming Steam Machine or Steam Controller that their personal data got swept up in a breach at CEVA Logistics, the French shipping giant that handles delivery for a huge chunk of European e-commerce.

The breach happened between July 29 and August 1, according to Valve's email to affected customers. Valve says it learned about the intrusion on August 7 and has been pressing CEVA for details on the full scope of what was taken.

The exposed data includes names, home addresses, phone numbers, email addresses, and order details, per Valve's notice, which was posted to Reddit and reported by Engadget. Valve was clear that CEVA never had access to payment information, Steam passwords, or Steam Guard codes, so account security itself isn't at risk. Customers don't need to change their passwords.

What customers do need to do is get suspicious. Valve told users to expect fake emails, texts, and phone calls impersonating Steam, Valve, or a delivery company. According to The Verge, these scam messages may quote a victim's actual address back to them to seem legitimate, then ask for a small customs or redelivery fee or push a link to "verify" the order. Valve's guidance is blunt: treat all of it as fake. The company only handles account issues through help.steampowered.com and says it will never reach out over email, Steam chat, or Discord.

This isn't just a gaming story. TechCrunch's reporting shows the CEVA breach is a much bigger mess than one console preorder list. CEVA confirmed to TechCrunch that the intrusion hit at least eight of its European warehouses, and the company says the incident is still under investigation. CEVA brought in $18.3 billion in revenue in 2025 and operates over a thousand warehouses worldwide, so the fact that hackers got into any part of that operation is a genuine wake-up call about how much personal data flows through third-party logistics firms that most consumers have never heard of.

The list of companies now warning their own customers stretches well beyond Valve. Dutch retail giant Bol has told customers their data may have been exposed and warned of order delays and cancellations. Luxury retailer De Bijenkorf confirmed delays tied to the same breach. Banking giant ING, eyewear brand Ace & Tate, and soccer club Ajax have all reported that customer shipping information tied to CEVA was affected, according to TechCrunch.

A gamer in Amsterdam who preordered a Steam Machine, a soccer fan buying merch, and a bank customer expecting a new card in the mail all got caught in the same net because they all relied, one step removed, on the same shipping vendor.

Industry outlet FreightWaves reported the hack has also caused shipping delays across the affected warehouses, meaning this isn't purely a privacy problem. People's actual packages are stuck too.

CEVA's public statement to TechCrunch says its cybersecurity teams activated response protocols as soon as the intrusion was identified and that the investigation is ongoing. The company insists the operational damage is contained to the eight warehouses and that no other global systems were touched. That's CEVA's own account of the scope. It hasn't been independently verified by any regulator yet, and Valve's own note says it's still pressing CEVA for the full picture of what was taken and how.

Valve says it's in the process of notifying data protection authorities in the affected countries, which under European rules like GDPR typically triggers formal review timelines and potential penalties if a company is found to have mishandled personal data or failed to secure it adequately. No fines or findings have been announced.

Valve spokesperson Doug Lombardi did not respond to TechCrunch's request for comment on the breach beyond the company's customer notice. CEVA has not released a full list of which retailers or how many customers were affected, and no total victim count has been made public. Until CEVA's investigation wraps and regulators weigh in, the honest answer is nobody outside the company knows exactly how big this actually is.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchA data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
center-left
EngadgetData of European Steam hardware customers 'likely compromised', Valve says
left
The VergeSteam hardware shipper breach leaks customer data, including names and addresses