Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Steam Customer Data Exposed in CEVA Logistics Cyberattack
Aug 10, 2026
6 Mins Read
Moon
Summarize with:

Steam Customer Data Exposed in CEVA Logistics Cyberattack

A cyberattack on CEVA Logistics, the company that distributes Steam hardware in Europe, may have exposed delivery and order information belonging to some Steam customers. Valve said the incident occurred between July 29 and August 1, 2026, and began notifying potentially affected customers on August 10.

Valve’s systems were not breached, and CEVA did not hold Steam passwords, Steam Guard codes, or payment information. However, the combination of names, addresses, contact details, and hardware order information creates a credible risk of targeted phishing, delivery fraud, and impersonation.

What Happened in the CEVA Logistics Cyberattack?

Valve’s customer notice states that the attack affected CEVA between July 29 and August 1. CEVA receives limited delivery information from Valve to ship physical hardware to European customers and retains relevant order data for up to 90 days.

Steam data breach email (Source)

Steam data breach email (Source)

Valve learned on August 7 that information belonging to certain Steam customers was likely involved. It then notified customers whose recent hardware orders may have fallen within CEVA’s retention period. CEVA isolated the affected systems, took them offline, and brought in external investigators, while Valve began notifying relevant data protection authorities.

What Steam Customer Data May Have Been Exposed?

According to Valve, the potentially compromised information includes:

• Customer names

• Street addresses, postal codes, cities, and countries

• Telephone numbers

• Email addresses associated with Steam accounts

• The type and price of the Steam hardware ordered

CEVA did not have access to Steam passwords, Steam Guard codes, payment details, or information about unrelated Steam purchases. Valve therefore said customers do not need to change their Steam passwords solely because of this incident.

Steam Order Data Phishing Risk

Delivery themed scams commonly claim that a parcel requires confirmation, a customs payment, or a redelivery fee. The exposed CEVA data could make those messages much more convincing because an attacker may know the recipient’s name, address, telephone number, Steam linked email address, product, and purchase price.

A criminal could impersonate Steam, Valve, CEVA, or a courier and direct the customer to a fraudulent payment or login page. Quoting an accurate address or hardware order may create a false sense of legitimacy, but it does not prove that a message came from the real company.

Steam users discussing the notification on Reddit and in a second community thread raised concerns about telephone numbers and high value product details. These comments do not show that the data has been misused, but they illustrate the forms of fraud customers expect after the disclosure.

The disclosure of a high value hardware order may also reveal that a household recently received expensive electronics. There is no public evidence that the incident has led to physical theft, but customers should remain cautious about unexpected delivery calls, messages, or visitors.

Was CoinbaseCartel Connected to the Steam Customer Data Exposure?

CoinbaseCartel is a plausible suspect because the group previously listed CEVA Logistics as an alleged victim in September 2025. However, neither CEVA nor investigators have attributed the July-August 2026 cyberattack to the group, so the connection remains unconfirmed.

CoinbaseCartel emerged in September 2025 as a financially motivated, data theft extortion group. Rather than encrypting systems, it steals corporate information and threatens to publish it unless the victim pays. By April 2026, the group had claimed more than 160 victims, with stolen credentials from infostealer logs believed to have supported much of its activity.

The earlier CEVA listing makes CoinbaseCartel relevant to the investigation, but it does not prove that the group conducted the latest attack. It is also important to distinguish the affected organizations: Steam was not breached. The attack targeted CEVA, and delivery information belonging to some Steam customers was likely compromised through CEVA’s systems.

What Should Affected Steam Customers Do?

Valve said affected customers do not need to change their Steam passwords based only on the information known so far. They should nevertheless remain alert to messages that use genuine delivery details.

• Open Steam Support by manually entering help.steampowered.com.

• Avoid login links received through email, SMS, Steam Chat, or Discord.

• Never provide a password or Steam Guard code to a courier or support representative.

• Reject unexpected customs, delivery, or redelivery payment requests.

• Verify shipment changes through the official Steam account and courier website.

• Treat a caller’s knowledge of a real address or order as potentially stolen context, not proof of identity.

Anyone who entered credentials or payment information on a suspicious site should immediately change the affected password, revoke active sessions where possible, review the account for unauthorized activity, and contact the relevant payment provider.

What Should Organizations Learn From the CEVA Breach?

Third-party risk assessments should cover more than whether a vendor can deliver a service. Organizations need to understand which customer data a provider receives, where it is stored, who can access it, and how long it remains available.

• Minimize the personal and commercial data shared with fulfillment providers.

• Set enforceable retention and deletion requirements across systems, exports, and backups.

• Require rapid incident notification and coordinated customer communication in vendor contracts.

• Assess identity, cloud, file transfer, and integration security, not only endpoint controls.

• Monitor suppliers for leaked credentials, criminal claims, and exposed internet facing assets.

• Segment warehouse and customer processing systems from broader operations.

• Test how quickly data transfers to a compromised provider can be suspended.

SOCRadar’s Supply Chain Intelligence can help organizations monitor risks across external vendors, while Attack Surface Management identifies exposed assets and weaknesses that may create entry points. Identity & Access Intelligence and Dark Web Monitoring add visibility into compromised credentials, infostealer data, and threat actor claims involving an organization or its suppliers.

Frequently Asked Questions

Was Steam Hacked?

No. Valve said the affected systems belonged to CEVA Logistics, its European hardware distribution partner. Steam’s own systems were not reported as compromised.

What Steam Customer Data May Have Been Exposed?

The information may include names, addresses, countries, telephone numbers, Steam linked email addresses, and the type and price of hardware ordered.

Were Steam Passwords or Payment Details Stolen?

According to Valve, CEVA did not have access to Steam passwords, Steam Guard codes, payment information, or information about unrelated Steam purchases.

Was CoinbaseCartel Behind the Latest CEVA Attack?

There is no public evidence attributing the July-August 2026 attack to CoinbaseCartel. The group separately listed CEVA as an alleged victim in September 2025, but that claim was not publicly confirmed by CEVA.

What Scams Should Affected Customers Expect?

Customers should watch for fake delivery, redelivery, customs payment, and Steam verification messages. Attackers may quote genuine names, addresses, products, or prices to make those communications appear authentic.