HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Data Breach at CEVA Logistics Exposes European Steam Customers’ Personal and Order Information

CEVA Logistics, the shipper for Valve’s Steam hardware in Europe, was hit by a cyberattack that exposed names, addresses, phone numbers, emails and order details of customers. The breach highlights the need for robust vendor‑risk controls and continuous audit evidence under SOC 2.

LiveThreat™ Intelligence · 📅 August 10, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Data Breach at CEVA Logistics Exposes European Steam Customers’ Personal and Order Information

What Happened — Between July 29 2026 and August 1 2026, CEVA Logistics – the third‑party shipper used by Valve for Steam hardware deliveries in Europe – suffered a cyberattack. Attackers accessed delivery records that include names, street addresses, phone numbers, email addresses and the type/price of ordered hardware. Valve has begun notifying affected customers and warns of follow‑up phishing attempts that reference the leaked data.

Why It Matters for Compliance & Audit Readiness

  • This incident is a textbook example of a third‑party data exposure that SOC 2 vendor‑management controls are designed to detect, monitor, and evidence.
  • Continuous monitoring of vendor security posture provides audit‑ready proof that due‑diligence was exercised before the breach.
  • Mapping the breach to the SOC 2 CC6.1 (Vendor Management) control helps organizations demonstrate that they had appropriate contracts, risk assessments, and ongoing oversight in place.

Who Is Affected — Video‑game publishers, digital distribution platforms, and any organization that relies on third‑party logistics for customer‑facing hardware shipments; primarily European consumers of Steam hardware.

Recommended Actions

  • Review and update your vendor‑risk management program to include real‑time security monitoring of logistics partners.
  • Map the CEVA incident to SOC 2 CC6.1 and collect evidence of vendor assessments, contractual security clauses, and incident‑response communication.
  • Conduct a targeted phishing awareness campaign for customers whose data may have been exposed.

Source: Help Net Security

Technical Notes

  • Attack vector: unauthorized access to CEVA’s internal systems (details pending).
  • Exfiltrated data: personal identifiers (name, address, phone, email) and order details (product type, price). No payment credentials or authentication tokens were compromised.

Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/08/10/valve-data-breach-ceva-logistics-steam-hardware/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →