Hackers Skipped Steam Entirely — Robbed Valve’s Delivery Guy Instead
They didn’t crack Valve. They didn’t even try. They walked in through the company that packs your boxes.
Break-in window: July 29 → Aug 1, 2026. Loot: your name, home address, phone number, plus the exact gadget you bought and the exact price you paid. Also caught in the net: ING bank, football club Ajax, retailer Bol, and eyewear brand Ace & Tate.
Honestly, this is the oldest trick in the book wearing a new hoodie. If the bank’s front door is a vault, you don’t drill the vault — you rob the guy delivering pizza to the bank. Hackers hit Ceva Logistics — the giant shipping company that mails out Steam Decks and a hundred other brands’ packages across Europe — and grabbed everyone’s info in one shot. Valve is now emailing every affected customer. Good times.

🧩 Dumb Mode Dictionary
| Word they use | What it actually means |
|---|---|
| Supply-chain attack | Instead of hacking you, they hack a smaller company you trust that already has your stuff |
| Ceva Logistics | The delivery/warehouse company that ships packages for tons of big brands (owned by shipping giant CMA CGM) |
| PII | “Personally Identifiable Info” — your name, address, phone, email. The stuff scammers dream about |
| Phishing / smishing | Fake messages (email = phishing, text = smishing) tricking you into clicking or paying |
| Third-party / vendor | Any outside company a business hands your data to. Weakest link in the chain |
🔍 What actually got taken (and what didn't)
The good news first — this one could’ve been way worse:
Stolen: full name, street address, phone, email, the product you ordered, and its price
NOT stolen: passwords, credit cards, bank account numbers (IBANs), Steam usernames
So nobody’s draining your account tomorrow. But here’s the sneaky part — they know you personally bought, say, a Steam Deck for €549, and they know where you live. That’s not enough to rob you directly. It’s perfect bait to trick you into robbing yourself. More on that below. Full breakdown at Help Net Security.
🗓️ How we got here
- Jul 29–Aug 1: attackers sit inside Ceva’s servers for roughly 3 days
- Aug 1: Ceva tells European retailers a cyberattack knocked out 8 of its warehouses
- Aug 10: Valve starts notifying Steam hardware buyers
- Ceva keeps order data for 90 days, so anyone who ordered in that window got looped in
This wasn’t a Valve screw-up. Valve’s own systems were fine. The hole was in the delivery partner — and that’s exactly why these hits keep working. You can lock your own house and still get robbed through the babysitter’s keys. The Record has the ripple map.
📊 The receipts
| Number | What it is |
|---|---|
| ~3 days | How long hackers roamed Ceva’s servers |
| 8 | European warehouses knocked offline |
| 90 days | How long your order data sat there waiting to leak |
| 15 million | Shipments Ceva handled last year |
| $18.3B | Ceva’s 2025 revenue (this is not a small player) |
| 1,000+ | Warehouses Ceva runs worldwide |
🗣️ What the timeline's saying
Okay but seriously — the security crowd isn’t shocked, they’re tired. The vibe across TechRadar and The Register:
- “One breach, a dozen brands. That’s the whole point of hitting a shipper.”
- Banks (ING) and a football club (Ajax) in the same leak as gamers — because they all use the same delivery plumbing
- The real fear isn’t this leak — it’s the wave of fake delivery texts that always follows
- Nobody outside security noticed until Valve’s email hit inboxes
Cool. Some Warehouse in Europe Sold Out Half of Steam. Now What the Hell Do We Do? ( ͡° ͜ʖ ͡°)

Every breach like this opens a short window where regular people are confused, scared, and Googling. That confusion is the opportunity — not to scam anyone, but to be the calm, useful person who shows up first. Here’s five ways to ride it clean.
🕳️ The Vendor Backdoor Cartographer
Big brands never announce which shipping/warehouse company handles their packages — but it’s hiding in plain sight. Public import records and LinkedIn job posts (“hiring warehouse ops at [Vendor] for [Brand]”) quietly reveal who ships for who. Map it. When one vendor gets popped, you instantly know every downstream brand that’s exposed — before the news does.
Example: A 24-year-old logistics nerd in Portugal builds a plain spreadsheet linking brands to their shippers using free tiers of ImportGenius and public LinkedIn job listings. When a vendor breach drops, he sells his “here’s who else is exposed” early-warning list to a fintech’s security team for a monthly retainer.
Timeline: First paying subscriber in 3–4 weeks of quiet building. Stays useful for a year+ — supply-chain breaches aren’t slowing down. Plateau hits when the big threat-intel firms copy the idea.
📡 The Breach-SEO Landgrab
When a breach hits, thousands of scared people type “was I in the Ceva breach?” into Google — and find nothing but paywalled news and corporate mush. Be the one clean, plain-English page that answers it. First mover grabs the search ranking while everyone else is still writing press releases.
Example: A student in the Philippines spins up a free one-page site on Carrd titled “Steam / Ceva Breach — Were You Affected? (Plain English).” Links to the official notice, explains what to do, and quietly runs an affiliate link to a breach-monitoring service like Have I Been Pwned’s partners. Ad + affiliate income while the traffic spikes.
Timeline: Traffic peaks within days of the news. Money for 4–8 weeks until the story dies. Rinse and repeat on the next breach — there’s always a next one.
🪟 The Patch-Window Smish Shield
Here’s the ugly truth: 2–4 weeks after a breach, scammers flood victims with fake “your package is delayed, pay €2 customs” texts. People fall for it because they actually did order something. Sell a dead-simple cheat card that teaches folks to spot the fake in 5 seconds — before the scam wave crests.
Example: A 27-year-old in Nigeria makes a clean 2-page “Spot the Fake Delivery Text” PDF (real shipper links vs fake, red flags, what to never click) and sells it for $4 on Gumroad, promoting it in gaming subreddits like r/Steam right when the panic emails land.
Timeline: Sales spike the week Valve’s emails go out. Fades in ~a month. Keep the template — every future breach reopens the window.
🎣 The Trap-Flipper Directory
The core problem: people can’t tell a real tracking link from a fake one. So build the reference nobody else made — a crowdsourced, verified list of the real sender addresses and domains major shippers actually use. Now anyone can check “is this text legit?” in one glance. Be the phone book for “is this real.”
Example: A 22-year-old in Brazil starts a public, community-edited Google Sheet listing verified official domains/sender IDs for the top 20 couriers, cross-checked against a spam-lookup tool like Truecaller. Grows it into a tiny site, funds it with a tip jar and one courier-comparison sponsor.
Timeline: Slow first month, then it snowballs as people share it during scam waves. Becomes a lasting SEO anchor if you keep it updated. This one can actually stick for years.
🛒 The Weak-Link Scorecard
Small online shops have NO idea if their shipping partner is a walking security risk. You do — because breach history is public. Sell tiny e-commerce owners a one-page “is your delivery/warehouse partner a breach risk?” report, built from free public breach trackers. Boring? Yes. Boring pays.
Example: A 26-year-old in India offers a €40 “Shipping Partner Risk Check” to Shopify store owners, pulling data from Have I Been Pwned and public breach roundups like PrivacyGuides, then hands over a clean 1-pager with a red/yellow/green score.
Timeline: First few clients within 2 weeks via cold DMs. Steady side income as long as breaches keep making headlines (forever, basically). Scales if you templatize the report.
🛠️ Follow-Up Actions
| Want to… | Do this |
|---|---|
| Check if your email leaked | Search it on Have I Been Pwned |
| Read the official Valve notice | BleepingComputer’s writeup |
| Understand supply-chain hits | Wikipedia: Supply chain attack |
| Track new breaches for hustle fuel | PrivacyGuides breach roundup |
| Build a free landing page fast | Carrd or Gumroad |
Quick Hits
| If you… | Then… |
|---|---|
| Assume your address leaked — check the notice | |
| Don’t click. Go to the courier’s real site directly | |
| Run your email through HIBP | |
| Be first, be clear, be the calm one — pick a hustle above | |
| Audit your shipping partner’s breach history now |
They didn’t need your password. They needed the address on your box — and the pizza guy left the door open.
!