Skip to content

Valve cyberattack: Steam customer data potentially exposed

Person using a computer displaying an account breach alert on the screen in a brightly lit room.

Vigilance is essential. Even during summer and the holiday period, cybercriminals do not take time off. Valve was therefore hit by a major cyberattack between 29 July and 1 August 2026.

The company is now best known for Steam, its indispensable gaming platform. Malicious individuals gained access to the infrastructure of CEVA Logistics, the subsidiary responsible for transporting and delivering Steam hardware across Europe. If you ordered a Steam Machine or a Steam Controller, your personal data is likely to be affected by the breach.

Valve: personal data obtained by cybercriminals

If you are a Valve customer, you may already have received an unwelcome email. The company is currently notifying its European customers that their personal information may have been stolen in a major cyberattack. CEVA holds delivery-specific information needed to ship Steam products to European customers. As the company retains this data for up to 90 days after an order, in line with regulations, customers who recently purchased a Steam Machine or Steam Controller may be affected by this hack.

Which Valve customer data was exposed?

There is some good news to begin with: the attackers were unable to obtain customers’ bank details, payment data or passwords. However, they did gain access to other personal information. CEVA told Valve that the cybercriminals may have obtained customers’ first and last names, postal addresses, telephone numbers, the email address linked to their Steam account, as well as the identity and price of the product ordered.

Steam Machine and Steam Controller customers urged to stay alert

Unfortunately, this information could be extremely valuable to dishonest individuals. Steam customers are highly likely to receive text messages, emails or even telephone calls about their Steam order in the near future. As these communications may include accurate information, they could appear genuine. Valve is therefore urging customers to exercise the utmost caution.

According to the company, attackers could impersonate legitimate organisations in an attempt to demand customs charges or obtain even more personal information, particularly bank details. If you ordered a Steam Machine or Steam Controller, be more cautious than ever and do not share your personal data.

Comments

No comments yet. Be the first to comment!

Leave a Comment