HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Valve warns Steam hardware buyers: Shipping‑partner breach exposes names, addresses and order details

CEVA Logistics, the delivery partner for Steam hardware in Europe, suffered a cyber‑attack that leaked customers' personal and purchase information. The breach highlights the importance of SOC 2 vendor‑management controls and continuous monitoring of third‑party security posture.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 malwarebytes.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
malwarebytes.com

Valve warns Steam hardware buyers: Shipping‑partner breach exposes names, addresses and order details

What Happened — CEVA Logistics, the logistics provider that ships Steam hardware in Europe, suffered a cyber‑attack that exposed customers’ personal data (name, address, phone, Steam email, hardware type and price). The breach window was July 29 – August 1 2026; Valve learned of it on August 7 and began notifying affected buyers on August 10. No passwords or payment data were taken.

Why It Matters for Compliance & Audit Readiness

  • Third‑party data breaches are a classic SOC 2 vendor‑management scenario; you must demonstrate due‑diligence, continuous monitoring, and evidence that suppliers protect C‑type data.
  • The incident underscores the need for documented controls around supplier security assessments, contract clauses for breach notification, and audit‑ready evidence of ongoing oversight.

Who Is Affected – Gaming hardware purchasers in Europe (Steam Deck, Steam Controller, Steam Machine); logistics and retail partners handling the shipments.

Recommended Actions – Review your vendor‑risk program against SOC 2 CC6.1 (Third‑Party Management); ensure contracts require breach‑notification timelines and evidence of supplier security controls; add the exposed data fields to your incident‑response playbook and update customer‑notification procedures.

Technical Notes – Attack vector: compromise of CEVA’s internal systems (likely via credential theft or malware) leading to unauthorized export of order fulfillment records. No CVE or public exploit disclosed. Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/data-breaches/2026/08/valve-warns-steam-hardware-buyers-expect-fake-delivery-scams

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →