HR EN DE
NEWS SPORT BIZNIS SCENA LIFESTYLE TECH

Valve Warns: Hackers Stole Data of Steam Hardware Customers

Cyberattack on distributor CEVA Logistics compromised names, addresses, and order details. Valve urges users not to fall for scam attempts.

Foto: Wikipedia (Valve)
Summary
  • Between July 29 and August 1, 2026, hackers breached the systems of CEVA Logistics, the European distributor of Steam hardware.
  • Stolen data includes names, addresses, phone numbers, emails, and order details, but not passwords or payment information.
  • Valve warns users to expect fake emails, SMS, or phone calls requesting additional payments or login to fraudulent sites.
  • Users are advised not to share passwords and Steam Guard codes and to log in only via official Steam domains.

Steam hardware users across Europe, including those in Croatia, have been targeted by a hacker attack that hit logistics company CEVA Logistics, Valve's European distributor. On Monday, Valve sent an urgent alert to customers, revealing that personal data and hardware purchase details were stolen during the breach.

The attack occurred between July 29 and August 1, 2026, and Valve only learned on August 7 that hackers had accessed the database with shipping information. Although the most sensitive data such as passwords, payment information, and Steam Guard codes were not compromised, the stolen information facilitates sophisticated phishing attacks.

What Did the Hackers Steal?

CEVA Logistics retains shipping-related data for 90 days after an order is fulfilled. The breach exposed customers' first and last names, home addresses, phone numbers, email addresses, and the type and price of the ordered product, such as the popular Steam Deck handheld or older Steam Machine devices. Valve emphasizes that the distributor does not have access to payment data, passwords, or Steam Guard codes.

Valve's Warning: Expect Fake Messages

In an email bulletin to users, Valve sent an unequivocal message: "Expect fake messages-via email, SMS, or phone-that mention your hardware order and appear to come from Steam, Valve, or the delivery company." The company warns that scammers will likely request payment of additional customs or shipping fees, or ask users to log in to fake websites to "confirm" their order.

"They may cite your address to prove they're legitimate. They may ask you to confirm delivery, pay a small customs fee or redelivery charge, or log in somewhere to 'confirm' your order. Treat all of them as fake," Valve's email to customers reads.

Valve further reminds that Steam support will never ask for your password or Steam Guard code, and neither will delivery services. Users are advised to manually type official Steam addresses into their browser and avoid clicking links in suspicious messages. The official login domains are store.steampowered.com, www.steampowered.com, steamcommunity.com, and help.steampowered.com.

Distributor's Response

After discovering the hack, CEVA Logistics isolated affected systems and notified data protection authorities. External investigators have been hired to determine the full extent of the damage and prevent further breaches. Although there is no direct link to Croatia, the warning applies to all users who ordered Steam hardware in Europe, including Croatian customers.

FAQ
Were my payment details or password stolen? +
No. Valve confirms that CEVA Logistics does not have access to payment data, passwords, or Steam Guard codes, so those sensitive details were not compromised.
How can I recognize a fake message? +
Fake messages may contain your personal information like your address to appear convincing and may request additional payments or login to suspicious sites. Valve will never ask for your password, and you should only log in via official domains starting with 'steampowered.com' or 'steamcommunity.com'.
Should I change my Steam password? +
According to Valve, it is not necessary because password and account data were not exposed during this attack on the distributor.
What has CEVA Logistics done after the attack? +
CEVA Logistics isolated affected systems, notified relevant data protection authorities, and hired external experts to investigate the security breach.

Log in

You need to log in or register to comment.

Comments (0)
No comments yet. Be the first!
Search
Popular
Nedavno pretraživano
helsinški sporazum
liga prvaka
digitalni mediji
Login
Home
Prati nas na Googleu
Categories