SYS::ONLINE
Wasteland.
Briefs1833
Issues23
SinceFeb 2026
LIVE
▣ Breach CEVA-LOGISTICS-SUP 2026-08-10

Ceva Logistics: Third Party Warehouse Intrusion and Downstream Data Breach

"Ceva Logistics, the France-headquartered third-party logistics giant that booked $18.3 billion in revenue in 2025 and runs more than 1,000 warehouses worldwide, was breached in an intrusion that hit at least eight of…"

Ceva Logistics, the France-headquartered third-party logistics giant that booked $18.3 billion in revenue in 2025 and runs more than 1,000 warehouses worldwide, was breached in an intrusion that hit at least eight of its European contract logistics warehouses. Ceva confirmed the incident in a statement to TechCrunch, acknowledging that part of its European contract logistics operation was affected. The company's downstream customers are the ones absorbing the fallout: Dutch e-commerce firm bol, luxury department store De Bijenkorf, and Valve have all notified their own customers that personal data handled through Ceva may have been accessed or copied. TechCrunch additionally reports that banking group ING, football club Ajax and an eyewear retailer are among the affected Ceva clients. No threat actor has claimed the attack, no ransomware group has been named, and no source has published a total victim count.

What Happened

FreightWaves, citing a source close to the investigation, reports the intrusion disrupted operations at eight Ceva warehouses in Europe over the weekend of August 1, and that affected customers were formally notified on August 1. TechCrunch, attributing the timeline to FreightWaves, places the start of the hack on July 29. Valve's own customer notification email, reviewed by GamesIndustry.biz and reported via WN Hub, gives the tightest window of any source: it states the breach at CEVA ran from July 29 to August 1, with Valve itself informed on August 7.

Detection dates differ by victim, which is normal in a supplier-breach cascade and worth stating plainly rather than smoothing over. Bol says it was alerted on August 1. De Bijenkorf told NL Times the breach was "officially detected" on Monday morning, which places its own confirmation on August 3. Valve was told on August 7, roughly a week after the intrusion window closed.

Scope appears contained to contract logistics. FreightWaves' source states no other Ceva systems beyond the eight warehouses were affected, and that air, ocean, ground and rail transportation management continued without incident. That containment claim is corroborated in reporting by teiss and breakbulk.news, though all of it traces back to the same FreightWaves sourcing rather than an independent Ceva disclosure. Ceva had not commented publicly at the time FreightWaves published; the company's acknowledgement came later, via TechCrunch.

The blast radius was uneven. FreightWaves notes the impact varied by customer depending on how dependent each was on applications and services at the eight sites. In bol's case, the compromise touched two order-processing systems used at a single distribution centre. Bol emphasised that no bol systems were affected. The operational damage nonetheless spread: bol suspended all data exchanges with the partner, pulled part of its assortment from sale, cancelled some orders and delayed others. De Bijenkorf reported delays to orders, returns and refunds, and told NL Times that part of that delay stems from the partner shutting down specific data systems entirely to isolate the threat. Its stores and webshop stayed open. Notably, De Bijenkorf declined to name the partner publicly, saying only that it handles logistics "in the broadest sense of the word" and specifically ruling out a parcel carrier such as PostNL or DHL.

The Dutch Data Protection Authority is investigating, alongside other law enforcement agencies and the affected companies. Both bol and De Bijenkorf independently reported the incident to the Dutch DPA. Valve says it is seeking further detail from CEVA on the scale and mechanics of the breach while coordinating with data protection agencies in the affected countries.

What Was Taken

Every source that describes the data agrees on the shape of it: delivery and order metadata, not credentials or payment instruments.

Across the reporting, the exposed fields include names, home and delivery addresses, postal codes, cities, countries, phone numbers, email addresses used to place orders, order numbers and parcel tracking details. Valve's notification adds one field the retail notifications do not: the type and cost of the hardware purchased. Likely affected Valve customers are buyers of the Steam Deck, Steam Machine and Steam Controller in Europe.

All sources are consistent that payment card data, bank account numbers and passwords were not involved. Valve specifically states that no financial data, passwords, Steam Guard codes or other account information were compromised, and that customers do not need to change passwords or account settings. De Bijenkorf gave the same assurance on payment details, bank accounts and passwords. Bol says there is no indication payment data or passwords were compromised.

On volume, the honest answer is that no figure exists yet. None of the eight sources publishes a record count, and none of the affected companies has stated one. Treat any number circulating elsewhere as unsourced until a regulator filing or company notification carries it. The one quantitative anchor available is Valve's retention window: because CEVA retains delivery data for 90 days, Valve is notifying every customer whose order fell inside that window. That is a rolling quarter of European Steam hardware shipments, which sets a floor on the exposure for that customer alone without pinning it to a number.

There is also a definitional split in how victims characterise the loss. Bol and Valve describe data that may have been accessed or copied. De Bijenkorf is more guarded, saying it cannot rule out that names, contact details and order data fell into the wrong hands, and that it is still investigating whether any data was taken at all. Confirmed exfiltration has not been established uniformly across all affected customers.

Why It Matters

This is a textbook demonstration that a company's customer data perimeter extends to every logistics vendor that touches a shipping label. Bol's systems were never breached. De Bijenkorf's systems were never breached. Valve's systems were never breached. All three still had to issue customer notifications, file with a data protection authority and absorb the reputational hit, because the fulfilment layer holds the same PII the retailer does.

The cross-sector spread is the striking part. A single warehouse operator's contract logistics environment sat upstream of a retail marketplace, a luxury department store, a banking group, a football club and a video game hardware manufacturer. Those organisations share no threat model, no security team and no compliance regime, yet they now share one incident. TechCrunch frames logistics providers as a growing target for criminals interested in the physical layer, the ability to identify, reroute or hijack trucks and containers and feed goods to real-world theft crews. That reframes shipping metadata as more than a phishing input. Name, address, tracking number and item value, taken together, is a targeting package.

The operational cost is separate from the data cost and was arguably larger in the short term. Bol removed products from sale and cancelled orders. De Bijenkorf's returns and refunds backed up. Much of that disruption came not from the attacker but from the defensive response: the partner pulling systems offline to contain the intrusion, and bol severing data exchange as a precaution. Containment in a shared fulfilment environment is a revenue event for every tenant, not just the one that was breached.

Finally, note the disclosure asymmetry. The victim organisation stayed quiet while its customers did the public notification work. FreightWaves reported that Ceva had not commented publicly; De Bijenkorf actively withheld the partner's name. The vendor was ultimately identified through downstream retailer notices and press reporting rather than by the breached party. If you are a Ceva customer, you may have learned of this from a journalist before you learned of it from your supplier.

The Attack Technique

Not disclosed, and no source in this set claims to know it. There is no named initial access vector, no CVE, no phishing or credential-stuffing attribution, no ransomware branding and no extortion claim. No threat actor or group has been linked to the intrusion by any source here.

What can be stated from the reporting is limited but useful. The intrusion was on the contract logistics side rather than transportation management, which suggests the compromised environment was the warehouse and order-management application stack rather than corporate freight systems. Attacker access was sufficient to reach two distinct order-processing systems at a single bol distribution centre, and comparable systems at other sites, which points to lateral movement or shared access across the contract logistics estate rather than a single isolated application flaw. The dwell window described by Valve, July 29 to August 1, is short, which is consistent either with fast detection or with an attacker who moved directly to data collection. Bol's statement notes the warehousing partner immediately took measures to stop the unauthorized access and engaged external cybersecurity specialists once the incident was discovered.

Treat the absence of a ransomware claim as provisional. Extortion groups frequently post victims weeks after intrusion, and no source has ruled out an encryption or leak-site component.

What Organizations Should Do

  1. Inventory which vendors hold your customer PII, not just which ones hold your data. Fulfilment partners, 3PLs, print-and-mail providers and returns processors routinely receive full name, address, phone, email and order value. If you cannot name every third party holding a copy of your customer address book, you cannot scope a breach like this when it happens to you.

  2. Pre-negotiate breach notification SLAs with logistics and fulfilment vendors. Valve learned of an intrusion that ended August 1 on August 7. Contractual notification windows measured in hours, plus a named security contact, are the difference between notifying customers ahead of the press and after it.

  3. Audit and shorten vendor-side data retention. CEVA's 90-day delivery data retention is what expanded Valve's notification population from one week of shipments to a full quarter. Push suppliers to the minimum retention their operation genuinely requires, and verify deletion rather than accepting the policy on paper.

  4. Build and rehearse the kill switch for vendor data exchanges. Bol suspended all data exchange with the partner as a precaution and could keep other fulfilment sites running. That is only possible if the integration is segmentable and someone has practised pulling it. Test whether you can cut a single vendor connection without halting the business.

  5. Brief customer support and issue phishing guidance immediately, before the fraud starts. Valve's notice is the model: warn users about phishing referencing real orders and real addresses, and restate the exact channels through which you will and will not contact them. Attackers holding name, address, order number, item and price can construct delivery-problem lures that defeat normal scepticism. Where possible, add step-up verification on address changes and order reroute requests for the affected cohort.

  6. Treat shipping metadata as physical-security-relevant data. High-value item type plus delivery address is a theft targeting dataset. For expensive hardware shipments, consider suppressing item descriptions in fulfilment records, and coordinate with carriers on signature or ID requirements for the affected order population.

  7. Do not wait for a total record count before acting. No figure has been published by any party. Scope your own exposure from your own outbound data flows to the vendor, not from the breach headline.

Sources: A data breach at shipping giant Ceva Logistics is rippling across b... | Cyberattack on Ceva Logistics warehouses in Europe impacts retailer... | De Bijenkorf warns customers after possible data breach at logistic... | Bol orders disrupted after cyberattack on logistics partner trans.... | Data Breach at Ceva Logistics Causes Ripple Effects for Banks, Reta... | CEVA Cyberattack Hits Eight European Warehouses as Retailers Face D... | teiss - News - Cyberattack on Ceva Logistics warehouses disrupts sh... | Valve has confirmed that a cyberattack on CEVA Logistics led to a ...