Data Breach at CEVA Logistics Exposes European Steam Customers’ Personal and Order Information
What Happened — Between July 29 2026 and August 1 2026, CEVA Logistics – the third‑party shipper used by Valve for Steam hardware deliveries in Europe – suffered a cyberattack. Attackers accessed delivery records that include names, street addresses, phone numbers, email addresses and the type/price of ordered hardware. Valve has begun notifying affected customers and warns of follow‑up phishing attempts that reference the leaked data.
Why It Matters for Compliance & Audit Readiness
- This incident is a textbook example of a third‑party data exposure that SOC 2 vendor‑management controls are designed to detect, monitor, and evidence.
- Continuous monitoring of vendor security posture provides audit‑ready proof that due‑diligence was exercised before the breach.
- Mapping the breach to the SOC 2 CC6.1 (Vendor Management) control helps organizations demonstrate that they had appropriate contracts, risk assessments, and ongoing oversight in place.
Who Is Affected — Video‑game publishers, digital distribution platforms, and any organization that relies on third‑party logistics for customer‑facing hardware shipments; primarily European consumers of Steam hardware.
Recommended Actions
- Review and update your vendor‑risk management program to include real‑time security monitoring of logistics partners.
- Map the CEVA incident to SOC 2 CC6.1 and collect evidence of vendor assessments, contractual security clauses, and incident‑response communication.
- Conduct a targeted phishing awareness campaign for customers whose data may have been exposed.
Source: Help Net Security
Technical Notes
- Attack vector: unauthorized access to CEVA’s internal systems (details pending).
- Exfiltrated data: personal identifiers (name, address, phone, email) and order details (product type, price). No payment credentials or authentication tokens were compromised.
Source: Help Net Security