"Expect fake messages" - Valve's EU shipping partner suffers a data breach, so if you bought a Steam Machine or Steam Controller, you may need to be on guard
Customers who bought a Steam Controller or Steam Machine in Europe may have had their data stolen, as Valve has issued a warning to its customers in the region telling them to "expect fake messages". Thankfully, no one who ordered the best PC controller or best gaming PC contender has had their payment details breached, but more basic information could still lead to trouble. "Between July 29 2026 and August 1, 2026, a cyberattack hit CEVA Logistics, the company that ships Steam hardware to customers in Europe", says an email sent from Valve. "CEVA is still investigating this attack, but as Valve learned on August 7, certain information about Steam customers, including you, was likely compromised," read the email. Valve's statement goes on to explain that CEVA is one of the brand's partners for shipping its hardware to customers within the Europe region, and that because CEVA maintains its customer info for 90 days in the event of returns and problems, Steam customers are impacted. While no payment info seems to be on the chopping block, Valve has helpfully provided the details that have most likely been stolen:Your nameYour street address, postal code and cityYour countryYour phone numberYour email address — the same one your Steam account usesThe type and price of the ordered product (Image credit: Valve) Thankfully, Valve also assures in their email that "Additional information related to your Steam account or other purchases was not impacted". In an attempt to counter any harmful misuse of this customer information, the Steam Controller maker has said that people should expect to see fake messages that pose as being from Valve or Steam, or its delivery company. "They may quote your address back to you to prove they're genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign somewhere to 'verify' your order. Treat all of them as fake". (Image credit: Future / Duncan Robertson) Valve has said that it's pressing its European partner for more details on the full scale of the data breach, and it's notifying the data protection authorities in affected territories. However, neither CEVA nor Valve can point to a confirmed "how" this data breach happened. Thankfully, this does seem to be isolated to European territories, so US readers need not worry just now. Either way, this is a good excuse to caution anyone who might have ordered or pre-ordered a Steam Machine, Controller, or is thinking about the upcoming Steam Frame VR headset, so check all your emails from Steam thrice to ensure they're legit and you aren't accidentally playing into scammers' hands. If you're looking to build your own rig instead, you'll need to know more about the best CPU for gaming, the best graphics card, and the best RAM for gaming. [/url]
Customers who bought a Steam Controller or Steam Machine in Europe may have had their data stolen, as Valve has issued a warning to its customers in the region telling them to "expect fake messages". Thankfully, no one who ordered the best PC controller or best gaming PC contender has had their payment details breached, but more basic information could still lead to trouble. "Between July 29 2026 and August 1, 2026, a cyberattack hit CEVA Logistics, the company that ships Steam hardware to customers in Europe", says an email sent from Valve.
"CEVA is still investigating this attack, but as Valve learned on August 7, certain information about Steam customers, including you, was likely compromised," read the email.
Valve's statement goes on to explain that CEVA is one of the brand's partners for shipping its hardware to customers within the Europe region, and that because CEVA maintains its customer info for 90 days in the event of returns and problems, Steam customers are impacted.
While no payment info seems to be on the chopping block, Valve has helpfully provided the details that have most likely been stolen:
- Your name
- Your street address, postal code and city
- Your country
- Your phone number
- Your email address — the same one your Steam account uses
- The type and price of the ordered product

(Image credit: Valve) Thankfully, Valve also assures in their email that "Additional information related to your Steam account or other purchases was not impacted".
In an attempt to counter any harmful misuse of this customer information, the Steam Controller maker has said that people should expect to see fake messages that pose as being from Valve or Steam, or its delivery company.
"They may quote your address back to you to prove they're genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign somewhere to 'verify' your order. Treat all of them as fake".

(Image credit: Future / Duncan Robertson) Valve has said that it's pressing its European partner for more details on the full scale of the data breach, and it's notifying the data protection authorities in affected territories. However, neither CEVA nor Valve can point to a confirmed "how" this data breach happened.
Thankfully, this does seem to be isolated to European territories, so US readers need not worry just now. Either way, this is a good excuse to caution anyone who might have ordered or pre-ordered a Steam Machine, Controller, or is thinking about the upcoming Steam Frame VR headset, so check all your emails from Steam thrice to ensure they're legit and you aren't accidentally playing into scammers' hands.
If you're looking to build your own rig instead, you'll need to know more about the best CPU for gaming, the best graphics card, and the best RAM for gaming.
[/url]
What's Your Reaction?