Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Data Breach at CEVA Logistics Exposes European Steam Customers’ Personal and Order Information

CEVA Logistics, the shipper for Valve’s Steam hardware in Europe, was hit by a cyberattack that exposed names, addresses, phone numbers, emails and order details of customers. The breach highlights the need for robust vendor‑risk controls and continuous audit evidence under SOC 2.

LiveThreat™ Intelligence · 📅 August 10, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

Data Breach at CEVA Logistics Exposes European Steam Customers’ Personal and Order Information

What Happened — Between July 29 2026 and August 1 2026, CEVA Logistics – the third‑party shipper used by Valve for Steam hardware deliveries in Europe – suffered a cyberattack. Attackers accessed delivery records that include names, street addresses, phone numbers, email addresses and the type/price of ordered hardware. Valve has begun notifying affected customers and warns of follow‑up phishing attempts that reference the leaked data.

Why It Matters for Compliance & Audit Readiness

  • This incident is a textbook example of a third‑party data exposure that SOC 2 vendor‑management controls are designed to detect, monitor, and evidence.
  • Continuous monitoring of vendor security posture provides audit‑ready proof that due‑diligence was exercised before the breach.
  • Mapping the breach to the SOC 2 CC6.1 (Vendor Management) control helps organizations demonstrate that they had appropriate contracts, risk assessments, and ongoing oversight in place.

Who Is Affected — Video‑game publishers, digital distribution platforms, and any organization that relies on third‑party logistics for customer‑facing hardware shipments; primarily European consumers of Steam hardware.

Recommended Actions

  • Review and update your vendor‑risk management program to include real‑time security monitoring of logistics partners.
  • Map the CEVA incident to SOC 2 CC6.1 and collect evidence of vendor assessments, contractual security clauses, and incident‑response communication.
  • Conduct a targeted phishing awareness campaign for customers whose data may have been exposed.

Source: Help Net Security

Technical Notes

  • Attack vector: unauthorized access to CEVA’s internal systems (details pending).
  • Exfiltrated data: personal identifiers (name, address, phone, email) and order details (product type, price). No payment credentials or authentication tokens were compromised.

Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/08/10/valve-data-breach-ceva-logistics-steam-hardware/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →