Steam customers caught in supply-chain breach as hackers target logistics partner

Digital Journal· August 15, 2026

Valve has notified European Steam customers of a data breach originating from its logistics partner, CEVA Logistics, which occurred between late July and early August 2026. The incident exposed shipping-related information for hardware orders, highlighting the growing vulnerability of third-party logistics providers in the global supply chain. This breach underscores the critical need for robust third-party risk management as cybercriminals increasingly target the extended ecosystem rather than primary organizations.

Valve, the operator of the Steam gaming platform, reported that unauthorized access to CEVA Logistics systems between July 29 and August 1, 2026, compromised personal data associated with hardware purchases. CEVA Logistics, a subsidiary of the CMA CGM Group, is a major global player in the sector, operating approximately 1,000 warehouses and generating $18.3 billion in revenue in 2025. While Valve's internal systems remained secure, attackers successfully targeted the logistics provider responsible for fulfilling customer orders, gaining access to names, addresses, phone numbers, and specific product details.

Cybersecurity experts, including Anna Collard of KnowBe4, have identified this as a textbook supply-chain breach where threat actors exploit the interconnected nature of modern business ecosystems. Because logistics companies often hold sensitive operational and customer data to facilitate global trade, they have become high-value targets for criminals seeking a path of least resistance. The incident demonstrates that even companies with mature internal security programs are exposed to significant risk through their reliance on external vendors, contractors, and transportation partners.

The implications for the logistics sector are significant, as the stolen shipping data provides a ready-made toolkit for sophisticated phishing and social engineering campaigns. By using genuine shipping terminology and specific order details, attackers can create highly convincing fraudulent communications regarding delivery problems or verification requests. This breach serves as a stark reminder for the industry that third-party risk management is now as vital as perimeter security, requiring logistics firms to demonstrate higher levels of accountability and digital resilience to protect the integrity of the supply chain.

Read the full story at Digital Journal

Summary generated by RabbitReport AI from public reporting. The full article and original reporting belong to Digital Journal.