CEVA Breach Exposes Steam and Retail Shipping Data

CEVA Logistics said a cyberattack between July 29 and August 1 exposed delivery and order data tied to customers of brands including Valve’s Steam hardware shipments in Europe. Valve began warning affected customers on August 7, after learning that names, addresses, phone numbers, email addresses, and order details may have been taken. CEVA needs that shipping information to fulfill orders, so the stolen records give an attacker the exact details a real delivery partner would know. That makes fake emails, texts, or phone calls far more convincing when they reference a real address or order, turning logistics data into phishing fuel and parcel-scam bait. The breach sits in the shipping relationship, not just inside CEVA’s own network. If a retailer or hardware vendor uses CEVA for fulfillment, recent customers whose orders passed through that system can inherit both the fraud risk and the disruption from shipping delays and cancellations.

Part of the PlainSec briefing for 2026-08-10

Every edition of this story: CEVA Breach Exposes Steam and Retail Shipping Data

Sources