A shipping partner's breach becomes Valve's notice
Between July 29 and August 1, 2026, a cyberattack hit CEVA Logistics, the shipping company Valve uses to deliver Steam Deck, Steam Machine, and Steam Controller hardware to customers across Europe. Valve says it learned of the intrusion on August 7 and began emailing affected European customers directly on August 10, more than a week after the attack window closed.
The delay between breach and notice is not unusual for supply-chain incidents: Valve first had to establish that CEVA, not Valve's own systems, was the point of entry, then work out which of its own customers' records had passed through CEVA's servers. CEVA retains delivery data for up to 90 days after an order ships, which is why the exposure is bounded to customers who bought Steam hardware roughly within that window.
What was exposed, and what was not
Valve's notice lists what CEVA held: full name, street address, postal code, city, country, phone number, the email address tied to the customer's Steam account, and the type and price of the hardware ordered. That is enough detail to build a convincing, personalized phishing or delivery-fraud message, even without a single password in the mix.
Valve was explicit about what CEVA never had: account passwords, Steam Guard codes, and payment information were not part of the data CEVA processed to ship a box, so none of it was exposed. Valve has warned customers to expect follow-up scam attempts referencing their real order details by email, text, or phone, and to treat any message asking to confirm an address or pay a redelivery fee as suspect.
CEVA is a processor - Valve is still the controller
Under the GDPR, the distinction between a data controller and a data processor decides who answers for a breach. Valve is the controller: it decides what customer data gets collected and why. CEVA is a processor: it only holds the data Valve gave it, and only to do the one job Valve hired it for, getting a box to a doorstep. CEVA being the party that was actually hacked does not shift that liability away from Valve.
That is precisely why Valve, not CEVA, sent the notification email, and why Valve says it is alerting data protection authorities in every EU country where affected customers live. A processor's security failure is legally the controller's breach to report, on the controller's clock, under the controller's name.
The blast radius goes well beyond Steam
Valve is not CEVA's only client, and this is not a Steam-only incident. CEVA is part of the CMA CGM shipping group and operates at least eight warehouses across Europe. Retailers including bol and De Bijenkorf in the Netherlands have posted their own customer alerts tied to the same intrusion, and reporting on the breach describes it rippling into banks and other retail brands that route shipments through CEVA.
Every one of those companies is now in the same position Valve is: a vendor it does not operate, cannot audit in real time, and had no way to detect the intrusion inside, produced a customer-data incident it now has to explain to its own users under its own name.
The lesson for any EU business that outsources fulfilment
Any business that hands customer names, addresses, or order data to a third-party logistics, fulfilment, or shipping provider has effectively extended its own attack surface to that vendor's systems, without extending its own visibility into how well that vendor secures them. The CEVA incident shows the failure mode plainly: the breach happened in July, at a company most Steam customers had never heard of, and the retailer whose name customers trust was the one left explaining it in August.
The practical response is not to bring fulfilment in-house. It is to know, before an incident forces the question, which vendors hold live customer PII, what data retention window they operate under, and what your own notification obligations look like the day one of them gets breached. Valve's response, fast internal escalation, a direct customer email, and proactive contact with data protection authorities, is the standard every controller should be able to meet on short notice, not the exception.
Read next: A Police Dashboard on 700 Foreigners Sat Open | A Free Add-On Can Read Every Doc You Own



