- Valve says customer delivery details were exposed, but Steam accounts and passwords were not affected.
- There is, however, an important detail that should stop customers from immediately panicking: Valve says this was not a breach of Steam accounts.
- The incident also highlights a bigger problem facing the gaming industry and just about every other online business today.
Valve says customer delivery details were exposed, but Steam accounts and passwords were not affected.
Ordering a new gaming device should be straightforward: place the order, wait for the delivery, and eventually start playing. Unfortunately, some Steam Machine customers in Europe now have something else to worry about while waiting for their hardware.
Valve has warned customers that their shipping information was exposed following a cyberattack against CEVA Logistics, the company handling deliveries for the hardware. According to the sources, hackers accessed CEVA's logistics systems between July 29 and August 1, giving them access to information used to fulfill Steam hardware orders.
The stolen information reportedly includes customers' names, home addresses, phone numbers, email addresses, and details about the products they ordered. That also includes the type of product and its price. That is a substantial amount of information. A hacker knowing someone's name and address is bad enough, but knowing that person ordered a specific Steam Machine and how much they paid could make future scams much more convincing.
There is, however, an important detail that should stop customers from immediately panicking: Valve says this was not a breach of Steam accounts.
CEVA's systems were being used for shipping, so the company had access to the information necessary to get hardware delivered. According to Valve, the compromised systems did not contain Steam passwords, Steam Guard codes, account information, or details about other purchases.

So, was Steam itself hacked? Not according to the information currently available. The attack targeted Valve's logistics partner rather than Steam's own systems. Valve is essentially caught in the middle because customer shipping information was being handled by the company responsible for delivering the hardware.
The biggest concern now is what happens after the breach. With names, phone numbers, email addresses, delivery addresses, and order information in the hands of attackers, phishing attempts could become much harder to spot. Imagine receiving a call from someone who already knows the Steam Machine you ordered, the phone number attached to the order, and even your delivery details. That could sound legitimate at first glance.
But that is exactly what customers need to watch out for. Valve is warning affected customers to be cautious about unexpected calls, emails, or messages claiming to be related to their Steam Machine order. A scammer having accurate information about an order does not mean they are actually working for Valve.
Customers should not give out passwords, Steam Guard codes, payment information, or other sensitive details to anyone who contacts them unexpectedly. Suspicious messages should also be reported through official Valve support channels rather than responding directly.
The incident also highlights a bigger problem facing the gaming industry and just about every other online business today.
Companies can protect their own systems, but customer information often travels through several outside companies before a product reaches someone's doorstep. That means a security problem at one partner can quickly become a problem for another company—and its customers.
For now, the good news is that Steam accounts and passwords do not appear to have been part of this breach. Still, affected Steam Machine customers should keep their guard up over the coming weeks. After all, if a scammer already knows what hardware is sitting in the delivery queue, how easy would it be to make the next fake Steam message look completely real?






