Valve has notified some customers that their personal information may have been exposed following a cyberattack on CEVA Logistics, the company that ships Steam hardware to customers in Europe. The attack occurred between Wednesday, July 29, and Saturday, August 1, 2026. Valve learned which information had been exposed on Friday, August 7, and emailed customers it believes may have been affected. Valve said no payment card details, account passwords, or Steam Guard codes were accessed because that information is never shared with CEVA Logistics. The information potentially obtained by the attackers includes customers’ postal addresses, phone numbers, and email addresses. CEVA receives only the delivery-related details required to ship Steam hardware in Europe. CEVA Logistics may retain delivery information for up to 90 days after an order. Valve therefore contacted all customers it could reasonably assume were affected. Affected users do not need to cancel payment cards or change their Steam passwords. They should, however, remain cautious about fraudulent emails or phone messages concerning Steam products. Valve is still investigating the scope of the breach and how the information was taken. It is also notifying data protection authorities in the affected countries. CEVA has isolated the affected systems, taken them offline, and brought in outside investigators. Somali residents in Europe who recently ordered physical Steam hardware should watch for official messages from Valve and treat unexpected emails or text messages about Steam products with caution.