• 3 mins read
  • Published

Valve Warns Steam Deck Owners of Data Breach After CEVA Attack

Chris Slate Editor - Gaming Platforms & Editorial Analysis Next-Gen Gaming Blog

Post by Chris Slate

Valve Warns Steam Deck Owners of Data Breach After CEVA Attack Next-Gen Gaming Blog
Valve Warns Steam Deck Owners of Data Breach After CEVA Attack

Valve has started alerting Steam Deck, Steam Machine and Steam Controller buyers in Europe to a data breach that may have exposed personal details, following a cyberattack on its logistics partner

Valve has begun contacting customers who purchased Steam Deck, Steam Machine or Steam Controller hardware in Europe within the past 90 days, warning that a recent data breach may have exposed their personal information. The incident stems from a cyberattack on CEVA Logistics, the distribution partner responsible for shipping Valve's hardware across the continent.

Details of the Breach

According to Valve, the compromised data includes names, delivery addresses, phone numbers, email addresses and purchase details. The company clarified that Steam account passwords and payment information were not affected. Valve shares specific delivery-related information with CEVA Logistics to facilitate hardware shipments, and it is this data that is believed to have been accessed by attackers.

CEVA Logistics reportedly retains customer delivery data for up to 90 days, which is why Valve is notifying all potentially impacted customers who made hardware purchases during that period. The breach does not appear to affect customers outside Europe or those who bought hardware before the 90-day window.

Player Impact and Valve's Response

Valve is urging affected customers to be vigilant for fraudulent messages referencing their hardware orders. These could arrive via email, SMS or phone, and may attempt to impersonate Valve, Steam or delivery companies. Typical scams might request confirmation of delivery, payment of customs or redelivery fees, or ask users to sign in to verify their order. Valve advises treating all such messages as suspicious and not to provide any personal information or payment details in response.

The company is pressing CEVA Logistics for further details about the breach and has notified relevant data protection authorities. Valve has stated there is no need for customers to change their Steam passwords or adjust account settings at this time, as account credentials and payment data were not included in the compromised information.

Context and Ongoing Risks

This incident comes at a time when hardware security and platform reliability are under increased scrutiny. Earlier this year, Valve raised prices on the Steam Deck, which reportedly led to a significant drop in sales. The breach follows a broader trend of cyberattacks targeting gaming platforms and their partners, raising questions about the security of personal data in the industry. For comparison, issues around platform reliability have also affected other major players, such as when Xbox investigated a disc game outage that prevented offline play.

Valve has not provided a timeline for when a full investigation will be completed or whether additional measures will be introduced to prevent similar incidents in future. The company's immediate focus remains on customer notification and cooperation with authorities.

When a gaming platform or hardware provider suffers a data breach, the main risk for players is not usually direct account compromise, but rather the increased likelihood of targeted phishing attempts. Attackers often use stolen delivery or purchase details to craft convincing fake messages, hoping to trick users into revealing sensitive information or making fraudulent payments. Understanding how to recognise and avoid these scams is now an essential part of digital security for anyone buying gaming hardware online.

Related articles