Recently, Valve's European logistics partner, CEVA Logistics, suffered a cyberattack. European players who purchased hardware such as Steam Decks and controllers are at risk of having their logistics data leaked. Upon learning of the incident, Valve has sent warning emails to potentially affected users.
This leak is limited to logistics and delivery information, including user names, addresses, phone numbers, emails linked to Steam, and hardware order models and prices. CEVA retains order information for only 90 days. Steam account passwords, payment information, and Steam Guard codes remain completely secure, so players do not need to change their account passwords.
The cyberattack affected eight of CEVA's warehouses in Europe, causing widespread logistics delays. Valve is urging the logistics provider to verify the full scope of the leak and is simultaneously reporting to data protection authorities across Europe. The involved servers have been taken offline and isolated.
Valve warns affected users to be vigilant against targeted scams: criminals may use stolen order and address information to impersonate Steam or logistics companies, requesting fees or account login details via email, SMS, or phone calls. Official support will never proactively handle orders through email or Discord private messages. Ignore any suspicious messages and consult only through official Steam customer support channels if you have questions.

