Most of us are wise to phishing emails that don’t contain much personal information. Generic “your account is suspended” messages usually get binned on sight. But what about the phishing emails that use your real name and address, and reference the specific product you bought last month? Even for the most suspicious of people, that can be convincing.
It’s also the situation European Steam hardware buyers walked into this week. On August 10, Valve, the company behind the Steam gaming platform and Steam hardware, warned customers that a cyberattack had exposed names, home addresses, phone numbers, Steam email addresses, and details of their hardware orders.
It wasn’t Valve itself that got hacked. Rather, it was its shipping partner CEVA Logistics, which handles delivery of hardware from the gaming store. Passwords and payment information were not touched.
What got stolen
The attack window ran from July 29 to August 1, 2026. Valve learned about it on August 7 and started notifying customers three days later. CEVA stores delivery data for roughly 90 days after shipment, meaning anyone who received a Steam Deck, Steam Controller, or Steam Machine in Europe over the past three months could be affected.
The exposed information may include:
- Name
- Street address, postal code, and city
- Country
- Phone number
- Email address linked to the customer’s Steam account
- The type and price of the ordered hardware
Exact numbers are still unconfirmed. Neither Valve nor CEVA has said how many customer records were involved. Dutch retailers Bol and De Bijenkorf were reportedly told about the same CEVA incident on August 1 and warned their own customers.
Why shipping data is valuable to scammers
A scammer can send an email, text, or even make a phone call that references your genuine order and delivery address before asking you to pay a small customs or redelivery fee, confirm your delivery, or sign in to “verify” your order.
Scam or legit? Scam Guard knows.
Data like this is already widely traded online. Malwarebytes researchers found more than 7,500 compromised datasets containing over 8.4 billion records on the dark web during the first six months of 2026.
Not Valve’s first security incident
Although Valve’s own systems weren’t compromised, that doesn’t mean the consequences can’t be severe.
In May 2025, a threat actor called Machine1337 tried to sell what looked like a dataset of 89 million Steam user records for $5,000. The data turned out to be older SMS messages carrying expired two-factor codes, routed through a third-party intermediary Valve says it never partnered with.
Valve has suffered a direct breach in the past though. November 2011 saw one that exposed records from 35 million users, including usernames, emails, and encrypted credit card details.
What affected buyers should do
In an email to customers, Valve advises them to assume that any message referencing their recent Steam hardware order is fake. That covers email, SMS, and phone calls, even the ones that quote your address correctly.
Steam Support never contacts users through email, Steam Chat, or Discord, and only handles account problems through its help page.
So you don’t need to rush to reset your password, although it never hurts to use a strong, unique password and enable Steam Guard’s two-factor authentication. Instead, be skeptical of any unsolicited emails, texts, or calls about a recent Steam hardware delivery, even if they include details only a real customer would know.
Something feel off? Check it before you click.
Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
Try it free →

