Valve warns Steam hardware buyers: Shipping‑partner breach exposes names, addresses and order details
What Happened — CEVA Logistics, the logistics provider that ships Steam hardware in Europe, suffered a cyber‑attack that exposed customers’ personal data (name, address, phone, Steam email, hardware type and price). The breach window was July 29 – August 1 2026; Valve learned of it on August 7 and began notifying affected buyers on August 10. No passwords or payment data were taken.
Why It Matters for Compliance & Audit Readiness
- Third‑party data breaches are a classic SOC 2 vendor‑management scenario; you must demonstrate due‑diligence, continuous monitoring, and evidence that suppliers protect C‑type data.
- The incident underscores the need for documented controls around supplier security assessments, contract clauses for breach notification, and audit‑ready evidence of ongoing oversight.
Who Is Affected – Gaming hardware purchasers in Europe (Steam Deck, Steam Controller, Steam Machine); logistics and retail partners handling the shipments.
Recommended Actions – Review your vendor‑risk program against SOC 2 CC6.1 (Third‑Party Management); ensure contracts require breach‑notification timelines and evidence of supplier security controls; add the exposed data fields to your incident‑response playbook and update customer‑notification procedures.
Technical Notes – Attack vector: compromise of CEVA’s internal systems (likely via credential theft or malware) leading to unauthorized export of order fulfillment records. No CVE or public exploit disclosed. Source: Malwarebytes Labs