← All stories
● Covered by 7 sources · 8 reportsMedium impact8 negative

Cyberattack on CEVA Logistics Exposes European Steam Hardware Customer Data

🔄 Updated 45d ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • CEVA Logistics suffered a cyberattack from July 29 to August 1, 2026.
  • Personal data of European Steam hardware customers was compromised.
  • Exposed data includes names, addresses, phone numbers, emails, and order details.
  • Payment information and Steam account credentials were not exposed.
  • Valve warned customers to expect fake messages and phishing attempts.
  • Pokémon Center customers in the UK and Germany were affected.
  • The breach led to the cancellation of some Pokémon Center customer orders.
  • CEVA Logistics is a subsidiary of the CMA CGM Group.
  • CEVA Logistics operates 1,000 warehouses.
  • CEVA Logistics handled 15 million shipments last year.
  • CEVA Logistics reported $18.3 billion in revenue in 2025.
  • CEVA retains delivery-related information for up to 90 days.

Cyberattack on Shipping Partner

CEVA Logistics, a major shipping and logistics company and Valve's European hardware distributor, experienced a cyberattack between July 29 and August 1, 2026. Valve learned of the compromise on August 7. The incident affected CEVA Logistics' servers, allowing attackers to access information used for shipping hardware orders to Steam customers in Europe.

Customer Data Compromised

The cyberattack resulted in the likely compromise of personal information belonging to European Steam hardware customers. This data includes names, addresses, phone numbers, email addresses, and details about the products ordered. Valve clarified that sensitive information such as payment details, passwords, or Steam Guard codes were not accessed, as CEVA Logistics does not store this type of data.

CEVA Logistics retains delivery-related information for up to 90 days to cover fulfillment needs. The incident impacts customers who ordered Steam hardware devices in Europe.

Warning Against Phishing Attempts

Following the data breach, Valve has issued a warning to affected customers to anticipate fake messages via email, SMS, or phone. These messages may attempt to impersonate Steam, Valve, or delivery companies, potentially quoting customer addresses or asking for small fees or sign-ins to verify orders. Customers are advised that they do not need to change their Steam passwords or account details due to this breach.

Broader Impact on European Retailers

The cyberattack on CEVA Logistics extended beyond Valve, disrupting operations at eight warehouses across Europe and affecting other corporate clients. Companies such as Dutch e-commerce giant Bol, luxury department store De Bijenkorf, eyewear company Ace & Tate, and Amsterdam football club Ajax have also been impacted. The incident has caused shipping delays for various goods and raised concerns about data privacy for customers of these retailers.

Updates

🕒 2026-08-17 · new reporting from BleepingComputer
  • Pokémon Center customers in the UK and Germany were affected.
  • The breach led to the cancellation of some Pokémon Center customer orders.
  • CEVA Logistics is a subsidiary of the CMA CGM Group.
  • CEVA Logistics operates 1,000 warehouses.
  • CEVA Logistics handled 15 million shipments last year.
  • CEVA Logistics reported $18.3 billion in revenue in 2025.
  • CEVA retains delivery-related information for up to 90 days.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Pokémon Center is notifying customers in the UK and Germany about a data breach at its third-party logistics provider, CEVA Logistics, which exposed personal and order information. The breach led to the cancellation of some customer orders and compromised names, addresses, phone numbers, email addresses, and order details. This incident highlights the supply chain risks associated with third-party vendors handling sensitive customer data.

Ceva Logistics experienced a cyberattack on July 29, disrupting its European operations and affecting eight warehouses. The incident has impacted multiple customers, including Bol, De Bijenkorf, and Valve, with potential exposure of personal information such as names, addresses, and order details. This disruption highlights ongoing supply chain vulnerabilities and the risk of data breaches through third-party logistics providers.

A cyberattack on global freight company Ceva Logistics has disrupted shipments for major European retailers and potentially exposed customer data for Steam users. The incident affected operations at eight warehouses in Europe, causing shipping delays and raising concerns about data privacy.

Valve announced that personal data of some European Steam hardware customers was likely compromised in a cyberattack on its shipping partner, CEVA Logistics, between July 29 and August 1. The breach exposed names, addresses, phone numbers, emails, and order details, prompting Valve to warn customers about potential scam messages. This incident impacts European customers who purchased Steam hardware and highlights supply chain security risks.

Shipping giant Ceva Logistics experienced a cyberattack that began on July 29, affecting at least eight European warehouses and causing shipping delays. The incident also resulted in a data breach, compromising personal information of customers from various companies, including Valve, Bol, and ING.

Valve's European shipping partner, CEVA Logistics, suffered a data breach between July 29th and August 1st, potentially exposing personal information of customers who ordered Steam hardware in Europe. This incident could lead to increased phishing attempts targeting affected customers, as their names, addresses, phone numbers, and email addresses may have been compromised.

CEVA Logistics, Valve's European hardware distributor, experienced a cyberattack between July 29 and August 1, 2026, compromising personal information and hardware purchase details of Steam customers. Valve has warned affected customers to expect phishing attempts related to their orders, though sensitive payment and account login data were not exposed.

Valve is notifying European Steam hardware customers that their personal data was stolen in a cyberattack on its shipping partner, CEVA Logistics. The breach exposed names, addresses, phone numbers, email addresses, and product details, but not payment information or Steam account credentials.