Steam hardware shipper breach leaks customer data, including names and addresses
Executive Take
Valve's exposure here started with a logistics vendor, not its own systems. Any company shipping physical products should check how long partners retain customer data and who controls it.
Executive Summary
Valve notified European customers that its shipping partner CEVA Logistics suffered a data breach between July 29 and August 1. Names, addresses, phone numbers, and emails tied to Steam Machine and Steam Controller reservations may have been exposed. CEVA retains delivery data for up to 90 days after orders.
Why It Matters
Technology and cybersecurity leaders should note this breach came through a third-party vendor, not Valve's core systems. It shows customer data risk now extends deep into supply chain and fulfillment partners.
Bizquad Perspective
The real lesson isn't Valve's security, it's that most companies have no visibility into how long their shipping vendors hold customer data or how it's protected.