Steam Hardware delivery scams may look real after CEVA data breach

Steam Hardware delivery scams may look real after CEVA data breach

ethan Smith·8/11/2026·3 min read
Valve says a CEVA Logistics cyberattack may have exposed delivery details of European Steam Hardware buyers, creating a heightened risk of targeted phishing messages.

A delivery text that knows your address, hardware model, and recent order can feel like the real thing. That is precisely the danger Valve is highlighting after a cyberattack on CEVA Logistics, its European Steam Hardware shipping partner: exposed delivery data can make a fake “verify your order” request unusually convincing.

The attack occurred between July 29 and August 1, 2026, with Valve learning on August 7 that customer information was likely compromised. The potentially affected group is European customers who ordered Steam hardware while their delivery information remained in CEVA’s 90-day retention period. That data may include names, addresses, phone numbers, email addresses, and the type and price of the hardware ordered.

Valve says CEVA did not have access to payment information, Steam passwords, Steam Guard codes, or other Steam account data. So this is not a reason to panic-change an untouched Steam account. It is a reason to treat every unexpected delivery email, text, or call as hostile — especially one claiming to be from Steam, Valve, CEVA, a courier, or customs.

The telltale demand is familiar: click a link to unblock a package, sign in to confirm delivery, or pay a small customs, redelivery, or “verification” fee. Accurate personal details do not prove a message is legitimate; they may be the material scammers are using to build trust.

FinalBoss // Gear

Level up your setup

01Graphics cardson Amazon02Gaming laptopson Amazon03High-refresh gaming monitorson Amazon04Discounted game keyson Kinguin

Affiliate links · As an Amazon Associate, FinalBoss earns from qualifying purchases.

Check an order by opening Steam directly through the client or a fresh browser session, then reviewing purchase history and hardware order status. Do not use a link supplied in a message. If Steam’s own order page does not show the claimed delivery problem, regard the contact as fraudulent.

If you clicked but submitted nothing, close the page and check Steam directly. If you entered login details, a payment method, or a Steam Guard code, secure the relevant account immediately, review Steam activity and purchases, monitor the payment method, and retain screenshots of the message and URL for a phishing report.

The verdict: European Steam Hardware buyers should ignore delivery verification demands outside Steam’s official flow; this breach’s real threat is the scam that arrives next.

Was this worth your time?

e
ethan Smith
Published 8/11/2026