In short: Between July 29 and August 1, 2026, hackers breached European warehouses of logistics provider CEVA Logistics. Attackers accessed names, delivery addresses, phone numbers, and email addresses of Steam hardware buyers from Valve, customers of ING Bank, Ajax Amsterdam, De Bijenkorf, and Ace & Tate. Passwords and payment data were not compromised, but the stolen personal details enable highly targeted phishing attacks.
What Happened
The attack on CEVA Logistics began on July 29, 2026. By August 1 the company had notified its business partners; Valve was informed on August 7. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) received breach notifications from ten affected organizations by August 10.
CEVA Logistics is a major multinational operator serving hundreds of European brands. The company retains shipping data for up to 90 days after order fulfillment — that window determined whose data was at risk. If you purchased Valve hardware (Steam Deck, Valve Index, accessories) in Europe in the three months before the attack, your contact details likely passed through CEVA's compromised servers. For more on how personal data flows through third parties, see the LiMP VPN blog.
Which Companies Were Affected
CEVA confirmed that customer data from the following organizations was exposed:
- Valve / Steam — buyers of Steam hardware (Steam Deck, Valve Index, peripherals)
- ING Bank — customers who ordered physical products
- Ajax Amsterdam — fans who purchased official merchandise
- De Bijenkorf — one of the Netherlands' largest department store chains
- Ace & Tate — a popular European eyewear brand
- Five or more additional organizations that notified the regulator without making a public statement.
Valve clarified that CEVA had no access to Steam passwords, Steam Guard codes, or payment data. User accounts are secure, but personal contact details have been compromised.
What Data Was Exposed — and What Was Not
According to affected companies, the breach included:
- Full customer names
- Delivery addresses (street, city, postal code)
- Phone numbers
- Email addresses, including those linked to Steam accounts and banking services
- Order details: product category and price
- For corporate buyers: company name and VAT number
What was not affected: passwords, PINs, payment card numbers, CVV codes, or login credentials. CEVA operates as a logistics agent, not a payment processor, so transaction data remained protected.
The Main Threat: Targeted Phishing
Combining a real name, home address, email, and specific order details gives attackers everything for near-perfect phishing. A fraudulent message reading "Your Steam Deck failed customs inspection — click here to pay the fee" will include your actual name, correct address, and genuine order information — almost indistinguishable from a legitimate delivery notification.
Valve and affected retailers have warned: Steam support will never ask for passwords or Steam Guard codes. Any delivery-related message requesting fees or data confirmation should be verified by navigating directly to the official website — never by clicking links in the message.
How to Protect Yourself When Shopping Online
This breach shows that even trusting a reputable brand does not give you full control — data passes through warehouses, couriers, and logistics operators. Several measures reduce your exposure:
- Email aliases for orders: use alias addresses (SimpleLogin, Apple Hide My Email). If a provider is breached, only one alias is exposed — not your primary inbox.
- A dedicated delivery phone number: a virtual number limits targeted voice phishing calls.
- Verify delivery notifications independently: any message requesting "customs fees" or "data confirmation" — navigate to the official site directly, never follow the link.
- Breach monitoring: add your email to HaveIBeenPwned to learn about incidents early.
- A VPN at the network level does not prevent your address from leaking at a warehouse, but it hides your IP when browsing shops and reduces digital tracking before any purchase. See LiMP VPN features for details.
