Valve has disclosed a data breach affecting Steam hardware customers in Europe, stemming from a security incident at its shipping partner, CEVA Logistics. The breach resulted in the unauthorized access of customer data, although the exact nature and scope of the compromised information have not been publicly disclosed. This incident highlights the potential risks associated with third-party vendors and the importance of robust security measures throughout the supply chain. The breach was reportedly discovered and contained, with notifications being sent to affected individuals. Valve's response to the incident is crucial in mitigating potential harm to its customers. The company's actions serve as a reminder that organizations must be vigilant in protecting sensitive information, particularly when working with external partners1. This incident matters to practitioners because it underscores the need for proactive risk assessment and management of third-party relationships to prevent similar breaches.