Executive Summary
Between July 29 and August 1, 2026, CEVA Logistics, the shipping partner for Valve's Steam hardware in Europe, experienced a cyberattack that compromised customer data. The attackers accessed names, addresses, phone numbers, email addresses, and details of purchased products. Valve confirmed that sensitive information such as payment details and Steam account credentials remained secure, as CEVA does not have access to this data. Affected customers have been notified and advised to be vigilant against potential phishing attempts. This incident underscores the vulnerabilities in supply chain partnerships and the importance of robust security measures across all entities handling customer data. As cyberattacks targeting third-party service providers become more prevalent, organizations must ensure comprehensive security protocols are in place to protect end-user information.
Why This Matters Now
The breach highlights the critical need for organizations to secure their supply chain partners, as attackers increasingly exploit third-party vulnerabilities to access sensitive customer data. Immediate action is required to assess and fortify these external relationships to prevent similar incidents.
Attack Path Analysis
Attackers compromised CEVA Logistics' systems, gaining unauthorized access to customer data. They escalated privileges to access sensitive information, moved laterally within the network, established command and control channels, exfiltrated customer data, and impacted Valve's customers by exposing their personal information.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers gained unauthorized access to CEVA Logistics' systems, potentially through a supply chain compromise.
MITRE ATT&CK® Techniques
Supply Chain Compromise
Compromise Hardware Supply Chain
Application Layer Protocol: Web Protocols
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Phishing: Spearphishing Attachment
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 Rev. 5 – Supply Chain Risk Management Policy and Procedures
Control ID: SR-1
PCI DSS 4.0 – Maintain and Implement Policies and Procedures to Manage Service Providers
Control ID: 12.8
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.11
DORA – ICT Third-Party Risk Management
Control ID: Article 28
NIS2 Directive – Supply Chain Security
Control ID: Article 21
CISA Zero Trust Maturity Model 2.0 – Supply Chain Risk Management
Control ID: Supply Chain Risk Management
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Games
Gaming platforms face supply chain attacks exposing customer shipping data, requiring enhanced third-party vendor security controls and encrypted traffic monitoring capabilities.
Logistics/Procurement
Logistics providers are prime supply chain attack targets, necessitating zero trust segmentation, egress security controls, and multicloud visibility for customer data protection.
Consumer Electronics
Hardware retailers using third-party logistics face data breach risks through supply chain compromises, requiring threat detection and secure hybrid connectivity implementations.
Internet
Digital distribution platforms must implement cloud firewall controls and anomaly detection to prevent customer data exposure through compromised shipping partner networks.
Sources
- Valve notifies Steam hardware customers of a data breachhttps://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/Verified
- CEVA Logistics Security Rating, Vendor Risk Report, and Data Breacheshttps://www.upguard.com/security-report/ceva-logisticsVerified
- Valve Investigating Reported Leak of 89 Million Steam Accounts, Says Its Systems Were Not Breachedhttps://www.gadgets360.com/games/news/steam-user-accounts-data-leak-report-valve-responds-systems-breach-8418794Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Implementing Aviatrix Zero Trust CNSF could have significantly constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access would likely be limited to the compromised workload, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing access to sensitive data.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely be restricted, reducing the ability to access additional systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control channels would likely be detected and disrupted, reducing persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts would likely be blocked or limited, reducing data loss.
The exposure of customer data would likely be minimized, reducing the risk of phishing attacks and identity theft.
Impact at a Glance
Affected Business Functions
- Order Fulfillment
- Customer Support
- Logistics Management
Estimated downtime: 3 days
Estimated loss: N/A
Personal information of Steam hardware customers, including names, addresses, phone numbers, email addresses, and details of ordered products.
Recommended Actions
Key Takeaways & Next Steps
- • Implement a robust supply chain management program to assess and monitor the security posture of third-party vendors.
- • Enforce zero trust segmentation to limit lateral movement within the network.
- • Deploy egress security and policy enforcement to monitor and control data exfiltration attempts.
- • Utilize threat detection and anomaly response systems to identify and respond to suspicious activities promptly.
- • Conduct regular security audits and penetration testing to identify and remediate vulnerabilities.



