CEVA Logistics cyberattack
A cyberattack on logistics giant CEVA Logistics disrupted eight European warehouses and exposed customer shipment data belonging to downstream clients including Valve's Steam hardware store, Dutch retailer Bol, De Bijenkorf, Ace & Tate and football club Ajax.
- Victim
- CEVA Logistics
On 11 August 2026, reporting confirmed that a cyberattack on CEVA Logistics β the France-based global freight and contract-logistics operator β had disrupted eight of its European warehouses and exposed customer shipment data belonging to a chain of downstream clients. Because CEVA handles fulfilment and delivery on behalf of many retailers, the breach rippled outward: Valve's Steam hardware store, Dutch e-commerce group Bol, luxury department store De Bijenkorf, eyewear brand Ace & Tate and football club Ajax were among those reported affected.
What happened
Attackers accessed CEVA's systems between 29 July and 1 August 2026. On 1 August, CEVA told European retailers that the intrusion had disrupted operations at eight of its European warehouses, causing shipping delays. As the investigation progressed, it became clear that customer and shipment information processed by CEVA on behalf of its clients had also been exposed.
For Steam customers in Europe, Valve said it learned of the incident on 7 August and later notified affected buyers. The exposed data included names, postal addresses, phone numbers, email addresses, and the type and price of ordered products. Valve stated that passwords, payment-card numbers and Steam Guard two-factor codes were not affected, because that data is not shared with the shipping partner.
CEVA isolated the affected systems, took them offline, and engaged outside investigators. Valve said it was pressing CEVA for more detail on what was taken and how the breach occurred, and was notifying data-protection authorities in the affected countries.
Impact
- Operational disruption at eight European warehouses, causing shipment delays across multiple retail brands.
- Customer shipment data β names, addresses, phone numbers, emails and order details β exposed for buyers of several downstream clients, including Steam hardware purchasers in Europe.
- No evidence that passwords, payment cards, or two-factor codes were compromised.
Why it matters
The CEVA breach is a textbook illustration of third-party logistics risk: a single compromise at a shared fulfilment provider cascades to the customers of every brand it serves, none of which were themselves breached. For consumers, the exposure of name, address, phone and specific purchase details is a strong basis for targeted, convincing phishing and package-delivery scams. It underlines that retailers' data-protection obligations extend to the security posture of their delivery and fulfilment partners, and that a logistics operator sits on a concentration of personal data whose blast radius reaches far beyond its own customer list.
Timeline
Attackers access CEVA Logistics systems; intrusion activity continues through 1 August.
CEVA informs European retailers that a cyberattack has disrupted operations at eight of its European warehouses.
Valve learns that Steam hardware customers' shipment information handled by CEVA may have been exposed.
First public reporting emerges as the breach ripples across CEVA's downstream retail and e-commerce clients; Valve begins notifying affected Steam customers.
Wider reporting confirms exposed customer data across multiple European brands including Bol, De Bijenkorf, Ace & Tate and Ajax.
Sources
- therecord.mediahttps://therecord.media/ceva-logistics-cyberattack-bol-steam-debijenkorf-ace-tate
- techcrunch.comhttps://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/
- theregister.comhttps://www.theregister.com/cyber-crime/2026/08/11/cyberattack-on-logistics-giant-ceva-delivers-customer-data-into-the-wrong-hands/5286229
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/