Cybersecurity Aug 10, 2026Add to bookmarks

A European Valve contractor suffered a cyberattack exposing data of Steam Machine and Steam Controller buyers. Valve is notifying customers directly—at the worst possible time for its big hardware comeback.
A European supplier for Valve — CEVA Logistics, a company specializing in international logistics and transportation — suffered a cyberattack that compromised the personal data of Steam Hardware buyers, primarily those who owned a Steam Machine or a Steam Controller. Valve confirmed the incident by directly emailing affected customers. According to reports from Kotaku and BleepingComputer, the breach occurred at the subcontractor’s end, not at Valve itself: Steam servers are not within the scope of the reported incident.
Users who purchased Steam hardware (Steam Machine, Steam Controller) from the affected supplier. The exact nature of the exposed data — shipping addresses, purchase history, contact information — has not yet been publicly specified by Valve. Customer notifications are currently being sent out.
Supply chain attacks (supply chain vendor attacks) remain one of the hardest exposure vectors for end users to prevent. You have no visibility into the security practices of your preferred supplier’s subcontractors. This is the same vector used by attackers in recent major breaches (Ticketmaster via Snowflake, or multiple telecom operators via logistics partners).
What this means in practice: even if your Steam account is secured with a strong password and 2FA, your customer data held by a third party can be exposed without you being able to do anything to prevent it.
This breach comes at the worst possible time for Valve. The company led by Gabe Newell is in the midst of a hardware push with the Steam Machine 2 and the Steam Frame, whose announcements and pre-launches have fueled weeks of attention from the PC gaming community. A data leak of hardware buyers, even via a third party, directly undermines the reliability image Valve is trying to rebuild for its return to the living room.
The original Steam Machine program (2015–2018) already left a bitter aftertaste among its buyers. This incident reopens a symbolic wound.
Attacks targeting third-party suppliers (supply chain vendor attacks) have been documented as steadily increasing since 2022 by major threat intelligence reports (CrowdStrike, Mandiant, ENISA). The growing integration of digital supply chains multiplies entry points — CEVA Logistics manages logistics for dozens of tech companies across Europe.
Article produced by artificial intelligence, reviewed under human editorial control.
L'offensive hardware Valve 2026 : Steam Machine et Steam Frame