Hello there, hardware buyers, delivery-alert survivors, and everyone who has ever received a ‘small redelivery fee’ text that somehow knew too much.
The Steam hardware data breach reached customers through the least glamorous part of Valve’s business: getting a box from a warehouse to a front door. Valve told European hardware buyers that a cyberattack hit CEVA Logistics between July 29 and August 1. Valve learned about the incident on August 7, and affected customers shared the warning publicly on August 10.
According to the customer notice reproduced by affected users and reported by Eurogamer, the information likely compromised can include a buyer’s name, full address, country, phone number, email address, and the type and price of the Steam hardware order. Valve said CEVA did not have payment information, Steam passwords, Steam Guard codes, or additional Steam account data.
🦊 Kiki:
Of course the scammer does not need your password. They already know your name, what you bought, what it cost, and where you live. That is customer-service cosplay with your receipt taped to its forehead.
The package can spend ten days ‘moving through the network,’ but the scam apparently qualifies for same-day delivery.
🍪 Chip signs for a parcel, then notices the parcel has already signed for him.
The Steam hardware data breach entered through the loading dock
The attack hit CEVA’s systems. Valve’s notice says its own Steam systems and other purchases were unaffected. The breach is serious without expanding it into the much larger claim that Steam accounts or payment cards were stolen.
However, Valve still had to disclose the consequence because CEVA received the delivery data required to ship hardware in Europe. A platform’s security boundary extends to every vendor that handles customer information, including the company that prints labels and puts boxes on trucks.
Game Cookies recently covered a Discord logging bug that left private messages in local game files. This incident exposes the same uncomfortable pattern at a different scale: data can escape through a supporting service that most customers never think about.
🦊 Kiki:
Steam can lock the front door with two-factor authentication, then the delivery chain walks around back carrying your name, address, phone number, email, product, and price. The castle has Steam Guard. The loading dock has the map.
Everyone loves ‘frictionless fulfillment’ until the friction is the only thing stopping a stranger from knowing exactly which expensive box belongs at your house.
🍪 Chip installs a drawbridge in front of the mailroom and immediately loses the key.
A shipping record is a phishing script
The leaked fields become more dangerous when combined. A random message asking for a customs fee is easy to ignore. A message that names the hardware, repeats the price, quotes the address, and arrives while a customer is waiting for delivery can feel authentic.
Valve warned recipients to expect fake email, SMS, or phone messages claiming to come from Steam, Valve, or a delivery company. The notice specifically described requests to confirm a delivery, pay a small customs or redelivery fee, or sign in to verify an order.
That warning makes the Steam hardware data breach a social-engineering problem as much as a privacy incident. Attackers do not need to break Steam Guard when they can pressure a customer into handing over a code.
The official Steam account security guidance says Steam Support handles account issues through help.steampowered.com and will never ask users for passwords or Steam Guard codes. It also lists the official Steam login domains and recommends typing the address directly instead of following an unsolicited link.

🦊 Kiki:
A scammer quoting your address is supposed to trigger the little voice that says, ‘Well, they must be real.’ That is the whole trick. Personal data is stage dressing for a lie.
If a courier asks for a Steam Guard code, the correct delivery instruction is to launch the entire message into the sun.
🍪 Chip labels the quarantine bin ‘SUN’ and starts sorting very seriously.
The 90-day window needs careful reading
The customer notice says CEVA retains delivery information for up to 90 days after an order. Valve therefore contacted customers it could assume were affected. That explains the notification pool, but it does not publish a victim count or prove that every record held during that period was taken.
The Steam hardware data breach timeline contains four useful markers: the attack ran from July 29 to August 1, Valve learned about it on August 7, and customer warnings surfaced on August 10. The notice does not identify the initial access method, the exact exfiltration time, or the number of people affected.
⭐ Byte:
The 90 days measure CEVA’s stated retention window after an order. They do not measure the attack duration, the number of exposed customers, or the volume of stolen records. The four-day attack window and six-day gap before Valve learned about it answer different questions. None of those numbers should be turned into an affected-customer estimate.
CEVA was still investigating when the notice was sent. Valve said CEVA isolated affected systems, took them offline, and brought in outside investigators. Valve also said it was notifying data-protection authorities in the affected countries.
Valve’s warning is unusually useful
Most incident emails arrive wrapped in ‘we take security seriously’ padding. Valve’s version identifies the likely fields, names the scams to expect, explains which credentials were outside CEVA’s reach, and gives users concrete verification rules.
Valve also told recipients that they did not need to change Steam passwords or account settings solely because of this incident. Anyone who already followed a suspicious link or disclosed information has a different problem and should use Steam’s security steps: review authorized devices, sign out everywhere if needed, secure the linked email account, change compromised credentials, and scan the device for malware.
🦊 Kiki:
Credit where it is due: Valve sent customers an incident email that contains information instead of seventeen paragraphs of legal oatmeal. It tells you what criminals know, which lie may arrive next, and where real support lives.
That should be the minimum. Corporate breach notices have lowered the bar so far that a usable warning now feels like somebody found the secret ending.
🍪 Chip checks the legal oatmeal for Steam Guard codes and adds cinnamon instead.
What affected customers should do now
The Steam hardware data breach does not require panic. It requires suspicion with a checklist:
– Treat unexpected delivery, customs, redelivery, or account-verification messages as fake. Open the courier or Steam site by typing the known address yourself.
– Never share a Steam password or Steam Guard code. Use the official Steam Support site for account issues instead of email, Steam Chat, Discord, or a link in an incoming message.
– If you clicked a suspicious link or entered information, review authorized devices, secure the connected email account, change exposed credentials, and scan the device for malware.
– If you received only Valve’s notice and did not interact with a suspicious message, Valve says this incident alone does not require a Steam password change.
– Keep Valve’s notice and any suspicious messages as records. Report account abuse through Steam and delivery fraud through the relevant courier or local reporting channel.
– Treat accurate order details as evidence that someone has data, not evidence that the sender is genuine.
What the notice still leaves unanswered
CEVA’s investigation remains incomplete. Several details should stay open:
– The number of affected Steam hardware customers has not been published.
– Valve has not published a complete list of affected countries.
– The notice does not identify the initial access method or exact exfiltration scope.
– The notice does not say whether specific products or order dates faced greater exposure.
– No confirmed volume of scam attempts or customer losses was included in the notice.
– CEVA’s 90-day retention statement does not prove which records were present or taken.
🦊 Kiki:
Here is the part that always gets outsourced with the warehouse contract: the consequences still arrive under the brand the customer trusted. Nobody receiving a fake Steam delivery text is going to think, ‘Ah yes, a nuanced failure in third-party logistics governance.’ They are going to think Steam knew where I lived and somebody else knows too.
Vendors can carry the box. They cannot carry the reputation away.
🍪 Chip tries to hand the reputation to the courier. The courier marks it undeliverable.
In the end…
The Steam hardware data breach did not expose payment cards or Steam credentials according to Valve’s notice. It exposed the context that makes a fake request believable: who bought what, what it cost, where it was going, and how to reach the buyer.
CEVA’s breach shows why ‘no passwords were taken’ can be true while the risk remains immediate. Shipping data can turn a generic phishing attempt into a convincing continuation of a real order.
Valve’s warning gives customers a practical defense: distrust the message, type the official address, and keep codes private. The investigation still owes them the missing scale.
⚙️ Stay skeptical when a delivery message knows enough to feel official.
⚙️ Keep passwords, Steam Guard codes, and small ‘redelivery fees’ away from unsolicited links.
⚙️ And remember, the package may be delayed, but the scammer already has the tracking number.
🦊 Kiki · 🍪 Chip · ⭐ Byte · 🦁 Leo
Have a tip about gaming security, vendor breaches, or a suspicious delivery message? Contact Game Cookies here.


