
Steam Data Breach 2026: What Leaked and What to Do Now
Valve says a breach at its European shipping partner CEVA Logistics exposed names, addresses, phone numbers and emails from Steam hardware orders. Here is what leaked, who is affected, and how to spot the delivery scams that follow.
In this guide · 6 sections
Valve has begun emailing Steam customers in Europe about a data breach that did not happen at Valve. The company's shipping partner, CEVA Logistics, was compromised, and the delivery paperwork attached to Steam hardware orders was caught in it: names, home addresses, phone numbers and email addresses. No passwords, no card numbers and nothing from inside your Steam library. That sounds mild until you think about what a scammer can do with a verified home address and a parcel you are already waiting for.
What happened at CEVA Logistics
Valve's notice to affected customers points to an intrusion at CEVA Logistics, the third-party firm that handles European deliveries of Steam hardware, between 29 July and 1 August. CEVA retains delivery-related information for up to 90 days after an order ships, so Valve is treating European hardware customers whose orders fell inside that retention window as likely compromised.
The timing is the uncomfortable part. The breach landed only weeks after Valve opened reservations for the Steam Machine and the Steam Controller, which means the exposed records skew towards recent orders that have not been delivered yet. Those are precisely the customers most likely to believe a message about a delivery problem.
Exactly what data was exposed
- Full name as entered on the order
- Delivery address
- Phone number
- Email address
- Delivery details tied to the Steam hardware shipment
Who is affected
The notice covers people who ordered Steam hardware for delivery in Europe and whose shipping data sat with CEVA during the incident. If you only buy games and software on Steam, there is no physical shipment and no delivery record to leak. Customers outside Europe are not named in this notification, although the phishing wave it triggers is not bound by geography.
The scams that follow this kind of leak
Valve told customers bluntly to expect fake messages by email, text and phone, and warned that whoever contacts you may recite your address back as proof they are genuine. Here is what the follow-up fraud typically looks like.
- A failed-delivery notice asking you to reconfirm your address on a lookalike site
- A small customs, handling or redelivery fee that exists only to capture your card details
- An invitation to sign in and verify your order, pointing at a cloned Steam login page
- A phone call that opens with your real name, address and order to establish trust
- A move from email to SMS or a messaging app, where there are no headers to inspect
The reliable tell is the request, not the detail. Knowing your address proves nothing now. Valve does not charge a fee to release a parcel, and no courier on earth needs your Steam password.
What to do right now
- Treat every message about this order as hostile until proven otherwise, and never act through a link inside it
- Track parcels only from the courier's own site or app, typed in by hand, using your tracking number
- Refuse all fee requests: genuine customs charges are handled by the retailer or the courier's official portal, never through an SMS link
- Turn on Steam Guard and the mobile authenticator so a stolen password alone cannot open your account
- Review authorised devices in your Steam account settings and sign out anything unfamiliar
- If you already entered card details, call your bank, freeze the card and ask about a chargeback rather than waiting to see what happens
- Report the message to Steam Support from inside the client, then delete it
Why your address keeps leaking from companies you never chose
You bought from Valve, but your address lived at a logistics contractor. That is normal, and it is also where the risk has moved. Attackers target the least-defended link in a supply chain because the payoff is a clean, verified list of people who are expecting a delivery. Retention windows make it worse: a 90-day hold on delivery data means one bad week at a contractor exposes three months of customers.
A shopper cannot audit a vendor's contractors, but two habits genuinely reduce exposure. Ship to a parcel locker or pickup point rather than your home whenever the item allows it, and keep a dedicated email address for hardware orders so that a leak immediately tells you which retailer failed you.
Was my Steam password or payment card stolen?
No. Valve's notice limits the exposure to delivery information held by its shipping partner, and a logistics provider never stores Steam passwords or card numbers. Enabling Steam Guard is still worthwhile general hygiene.
I am not in Europe. Am I affected?
This notification covers Steam hardware orders shipped in Europe. Customers elsewhere are not named in it, but leaked lists circulate and the same delivery-scam scripts are worth recognising wherever you live.
How do I know whether my order was included?
Valve emailed the customers it believes were affected. Do not trust a message that claims otherwise. Open the Steam client or Steam Support directly and check your notifications and order history instead of following any link.
Should I change my Steam password anyway?
This incident does not require it. If you reuse that password anywhere else, change it there, because reuse is what turns an unrelated leak into an account takeover.
Can I have my delivery data deleted?
In Europe you can ask both Valve and CEVA Logistics what they hold and request erasure once the data is no longer needed for the delivery. The stated 90-day retention means most of it should age out by itself.
Does this affect Steam Machine and Steam Controller reservations?
The reservations themselves are unaffected. The risk is that recent hardware buyers make the most convincing targets for a fake delivery message, because they genuinely are waiting for a parcel.
Editor of Majumedia. I research and compare consumer tech, home, fitness and travel gear, digging through manufacturer specifications, warranty terms and long-term owner reports so buying guides reflect what a product is actually like to live with — not what the marketing says.


