Full Report
Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. [...]
Analysis Summary
# Incident Report: Supply Chain Compromise of CEVA Logistics (Valve/Steam)
## Executive Summary
Valve notified Steam hardware customers in Europe of a data breach originating from a cyberattack on its third-party shipping partner, CEVA Logistics. Attackers gained access to CEVA's servers, exfiltrating personal delivery information for customers who ordered hardware within a 90-day window. While physical delivery details were stolen, sensitive Steam account credentials and payment information remained secure as they were not stored on the compromised systems.
## Incident Details
- **Discovery Date:** August 7, 2026 (Valve notified by CEVA)
- **Incident Date:** July 29, 2026 – August 1, 2026
- **Affected Organization:** CEVA Logistics (Subsidiary of CMA CGM Group)
- **Sector:** Logistics and Supply Chain / E-commerce
- **Geography:** Europe (Multiple retailers and regions affected)
## Timeline of Events
### Initial Access
- **Date/Time:** July 29, 2026
- **Vector:** Not explicitly disclosed (Cyberattack on CEVA server infrastructure)
- **Details:** Attackers breached systems at CEVA Logistics used to manage hardware shipments for European retailers.
### Lateral Movement
- **Details:** Evidence suggests movement across systems managing at least eight European warehouses, disrupting regional operations.
### Data Exfiltration/Impact
- **Date:** July 29 – August 1, 2026
- **Details:** Attackers accessed and exfiltrated a 90-day archive of shipping data. Stolen information included names, physical addresses, phone numbers, email addresses, and order details (product type and price).
### Detection & Response
- **August 1, 2026:** CEVA informs retailers of operational disruptions at warehouses.
- **August 7, 2026:** Valve is officially informed that Steam customer data was likely compromised.
- **August 10, 2026:** Valve begins mass notification of affected customers and relevant Data Protection Authorities.
## Attack Methodology
*Note: Specific technical details regarding the breach of CEVA are currently under investigation.*
- **Initial Access:** Cyberattack on logistics servers (specific method TBD).
- **Collection:** Automated gathering of delivery-related PII stored in shipment databases.
- **Exfiltration:** Theft of data pertaining to customers from the previous 90 days.
- **Impact:** Operational disruption of 8 warehouses and a significant data breach of third-party client information.
## Impact Assessment
- **Financial:** Potential regulatory fines (GDPR) for CEVA; no direct financial theft reported for Steam customers.
- **Data Breach:** Compromise of PII (Names, Addresses, Phone numbers, Emails) and purchase history.
- **Operational:** CEVA operations at eight European warehouses were temporarily disrupted/taken offline.
- **Reputational:** Significant public concern for Valve/Steam customers regarding supply chain security.
## Indicators of Compromise
*Technical IOCs have not been publicly released by CEVA Logistics or Valve at this time.*
- **Behavioral Indicators:** Unexpected server downtime at CEVA; unauthorized access to historical shipping manifests.
## Response Actions
- **Containment:** CEVA isolated the affected systems and took them offline to stop further access.
- **Eradication:** Outside forensic investigators were brought in to purge the threat.
- **Recovery:** Notifying affected customers and data protection authorities.
- **Communication:** Valve issued clear guidance to users regarding the risks of targeted phishing.
## Lessons Learned
- **Third-Party Risk:** The security of a company is only as strong as its least secure logistics partner.
- **Data Retention Policies:** CEVA’s 90-day retention policy defined the scope of the breach; shorter retention windows could have minimized the volume of stolen data.
- **Communication Lag:** There was a 6-day gap between CEVA realizing operations were disrupted (Aug 1) and Valve being notified of the data breach (Aug 7).
## Recommendations
- **Vendor Risk Management:** Implement more stringent security audits and real-time monitoring requirements for high-volume logistics partners.
- **Phishing Awareness:** Customers should be warned that attackers may use specific order details (e.g., "You bought a Steam Deck") to add credibility to phishing SMS/emails.
- **Data Minimization:** Ensure partners only receive the absolute minimum data required for their specific function and enforce strict purging of PII immediately after delivery confirmation.