Steam customers caught in supply-chain breach as hackers target logistics partner
The latest data breach affecting users of the Steam gaming platform serves as a reminder that cybercriminals increasingly target the extended supply chain rather than the primary organisation itself. Valve, the company behind the Steam digital gaming ecosystem, is reportedly notifying European customers that personal information associated with hardware orders was exposed following a breach involving logistics company CEVA Logistics.
According to reports, affected customers began receiving notification emails warning that attackers gained access to information held by CEVA Logistics, a logistics and supply-chain company responsible for shipping hardware purchases to Steam customers. The unauthorised access reportedly occurred between July 29 and August 1, 2026. Details exposed are said to include shipping-related information used to fulfil customer orders.
The incident was first widely reported by cybersecurity publication BleepingComputer, which stated that Valve itself was not directly compromised. Instead, attackers allegedly gained access through CEVA Logistics systems. CEVA Logistics is a wholly owned subsidiary of the CMA CGM Group and operates approximately 1,000 warehouses worldwide, handling millions of shipments annually. According to company figures, CEVA generated revenues of approximately $18.3 billion in 2025.
The growing threat of supply-chain attacks
Cybersecurity experts often describe breaches of trusted suppliers and service providers as “supply-chain attacks”. Rather than directly attacking a protected organisation, threat actors identify third-party partners that may have access to valuable customer or operational data.
This approach has become increasingly common because modern businesses depend on complex ecosystems of vendors, cloud providers, logistics companies, contractors and technology partners. Even organisations with mature security programmes can become exposed if a trusted supplier experiences a security failure.
Anna Collard, CISO Advisor and Senior Vice President of Content Strategy at KnowBe4, characterised the incident as a classic example of a supply-chain compromise, in a statement sent to Digital Journal. “This is a textbook supply-chain breach. Valve itself wasn’t compromised, the attackers went after CEVA, its logistics partner. It’s a reminder that an organisation’s security is only ever as strong as the third parties it entrusts with customer data.”
Her observation reflects a broader challenge facing organisations across every sector. Many companies have invested heavily in internal cybersecurity defences but may have less visibility into the security practices of external providers.
Individuals who receive breach notifications should remain vigilant but avoid panic. Recommended precautions include treating unexpected delivery-related messages with suspicion, avoiding links contained in unsolicited emails or text messages, visiting retailer websites directly rather than through embedded links, and monitoring accounts for unusual activity.
Why the stolen information matters
While the breach does not appear to involve financial information or account credentials, the exposed information could still be highly valuable to cybercriminals. Collard warns that names, addresses, telephone numbers and product-order details create an ideal foundation for follow-on attacks.
“From a risk perspective, we need to think about what the stolen data enables next. Names, addresses, phone numbers and the specific product and price ordered are a ready-made toolkit for targeted phishing.”
This type of information allows criminals to create highly convincing fraudulent communications. Attackers may reference a victim’s real address, mention the exact hardware purchased or use genuine shipping terminology to make fake messages appear authentic.
The objective is often to persuade the recipient to click a malicious link, provide additional personal information or make a fraudulent payment.
Expect a wave of delivery scams
Supply-chain breaches frequently create opportunities for secondary campaigns involving phishing, smishing (SMS phishing) or social engineering. The most likely scenario following a logistics-related breach is a surge of delivery-themed scams. Because recipients may genuinely be waiting for hardware deliveries, these messages can be especially effective.
Collard notes: “I’d expect a wave of ‘delivery problem’ lures over the coming weeks, messages about a redelivery fee or a request to ‘verify’ an order.” Consumers should therefore be particularly cautious about unexpected communications concerning recent purchases.
While the affected customers appear to be European Steam hardware purchasers, the incident has wider relevance for Canadian businesses and consumers. Canada’s economy relies heavily on complex global logistics networks spanning manufacturing, transportation, e-commerce and critical infrastructure. Organisations increasingly share customer data with third-party fulfilment providers, couriers and supply-chain partners. As a result, supply-chain cybersecurity has become a growing area of focus for Canadian regulators and security professionals.
The incident demonstrates that even organisations with strong cybersecurity controls can face risk through indirect exposures. For Canadian companies, third-party risk management is increasingly becoming as important as perimeter security, endpoint protection or employee awareness training.
Steam customers caught in supply-chain breach as hackers target logistics partner
#Steam #customers #caught #supplychain #breach #hackers #target #logistics #partner