
Valve’s alert for European Steam hardware customers points to delivery information held by CEVA Logistics: treat your name, address, phone number, email address, and Steam hardware order details as information scammers may use against you. Valve says CEVA did not receive or expose Steam passwords, payment information, or Steam Guard codes, so the immediate threat is a convincing delivery scam rather than an automatic Steam account takeover.
The important split is simple: check your delivery-data exposure now, then secure your Steam account only if a suspicious message, fake site, or verification request caused you to share something after the breach.
| Category | What may be involved | What to do |
|---|---|---|
| Delivery and order data | Name, street address, postal code, city, country, phone number, email address, ordered hardware type, and product price. | Expect targeted email, SMS, and phone scams that use real order details to look legitimate. |
| Steam account credentials | Valve says passwords, Steam Guard codes, and other Steam account controls were not shared with CEVA. | There is no breach-only reason to reset your password if you have not interacted with a suspicious message. |
| Payment information | Valve says CEVA did not have payment data for these orders. | Treat any “reshipment fee,” customs payment, or card-verification request as fraud until independently confirmed. |
The distinction matters because an attacker with your home address, the model of hardware you ordered, and its price can make a fake parcel problem sound extremely believable. That information can be used to push you toward the part they actually want: a Steam login, a Steam Guard code, or card details entered on a fraudulent page.
Valve is notifying affected Steam hardware buyers in Europe and has also notified the relevant data-protection authorities. CEVA retained delivery data for up to 90 days, so a European Steam hardware order within that window should be handled as potentially exposed, even if a notification has not reached your inbox yet.
The exact overall scope is still being clarified, but this is enough information to act safely. You do not need proof that a specific scammer has your data before refusing delivery-related links and payment requests.

FinalBoss // Gear
Level up your setup
01Graphics cardson Amazon→02Gaming laptopson Amazon→03High-refresh gaming monitorson Amazon→04Discounted game keyson Kinguin→Affiliate links · As an Amazon Associate, FinalBoss earns from qualifying purchases.
Expect impersonation attempts by email, text message, and phone call. A real name, delivery address, Steam Machine order, Steam Controller order, or accurate price does not validate the sender; those are precisely the details that can be used to make the scam credible.
Do not reply to the message, call a phone number supplied in it, or use its tracking link. Open Steam yourself through the installed client or your normal browser bookmark, then use Valve’s official support and order channels to check for a genuine issue. Do the same with a carrier: find its official contact page independently rather than following the message.
Get access to exclusive strategies, hidden tips, and pro-level insights that we don't share publicly.
Ultimate Guide Strategy Guide + Weekly Pro Tips
Delete or report it, then remain alert for follow-up contacts. Scammers often send a second message with more urgency after the first one is ignored, claiming the parcel will be destroyed, returned, or charged for storage.
Close the page. Check whether it asked you to sign in, download a file, approve a code, or enter card details. With no credentials, payment data, or verification code submitted, the risk to your Steam account is lower; the main concern remains future phishing using the same delivery context.
Change your Steam password immediately through Steam’s official account path, not through the suspicious page. Review recent account activity where available, confirm the account email is still yours, and check Steam Guard and recognized devices. If that password was reused on any other service, change it there as well. This would be a separate credential-theft attempt triggered by phishing, rather than a password exposure from CEVA’s systems.

Treat the account as at risk immediately. Change the Steam password through the official service, re-secure Steam Guard, review account security settings, and make sure the recovery email and phone number have not been changed. A verification code can be the final approval a scammer needs after they have captured your password.
Contact the card issuer or bank promptly, explain that the details were entered on a suspected phishing page, and dispute unauthorized activity. Monitor for small test charges and unfamiliar subscription payments. Because CEVA did not have payment information for the affected Steam hardware deliveries, a payment demand tied to this incident is a major fraud warning.
Valve’s notice does not call for every affected buyer to change passwords or Steam Guard settings. A password reset becomes sensible when you reused the password elsewhere, entered it after clicking a suspicious link, shared a verification code, or see account activity you do not recognize.
Report suspicious delivery-themed emails, texts, and calls through the relevant official support or carrier reporting route, and preserve the sender address, phone number, and message contents for the report. The safest rule for this incident is to resolve every delivery issue from a service you opened yourself, never from a link or number delivered in an unexpected message.