Data Breach at Ceva Logistics Impacting Global Retail and Gaming
Ceva Logistics, one of the world's largest shipping and logistics providers, has suffered a significant cyberattack. The breach has exposed personal information of customers from multiple companies that rely on Ceva for product delivery, affecting sectors from banking to gaming.
Scope of the Attack
The cyberattack hit at least eight Ceva warehouses across Europe, disrupting the flow of goods throughout the region, according to a statement from the company to TechCrunch. Industry publication FreightWaves reported that the incident began on July 29, 2026, and is causing shipping delays for a wide range of products stored in the affected facilities.
Ceva, headquartered in France, reported $18.3 billion in revenue for 2025 and operates over a thousand warehouses worldwide. The company serves as a critical link in global supply chains, moving goods from assembly lines to consumer doorsteps.
Rising Threat to Logistics Industry
Shipping and logistics companies have become increasingly attractive targets for cybercriminals over the past several years. Attackers can potentially gain access to and hijack trucks and containers filled with merchandise, coordinating with real-world criminal networks for physical theft, as highlighted by cybersecurity firm Proofpoint in its threat research.
Customer Data Exposed
While the attack disrupted operations, the resulting data breach may have far-reaching consequences. Hackers accessed and exfiltrated sensitive personal information belonging to retail customers of companies that use Ceva's delivery services. This data typically includes names, home addresses, phone numbers, and email addresses used for order fulfillment.
Impacted Companies and Industries
Retail Giants Affected
Dutch online retail platform Bol confirmed that attackers breached systems of its warehousing partner, Ceva, and warned that customer data may have been compromised. The company also anticipates order delays and potential cancellations due to the incident. Similarly, De Bijenkorf, a luxury Dutch retailer, has acknowledged order delays following the theft of customer data, as reported by local media outlet NOS.
Other notable victims include football club Ajax, banking giant ING, and eyewear company Ace & Tate, all of which have reported that customers' shipping information was compromised.
Gaming Community Impacted
Valve, the company behind the Steam gaming platform, notified hardware customers that data was taken from Ceva's systems. The company alerted recent purchasers of Steam hardware that their personal information may have been exposed. Valve noted in its communication, which was circulated on Reddit, that Ceva retains shipping and delivery information for 90 days following an order.
Ongoing Investigation and Response
Valve spokesperson Doug Lombardi did not respond to a request for comment regarding the incident. As the investigation unfolds, affected companies are advising customers to monitor their accounts and be vigilant against potential fraud or identity theft.
This breach underscores the increasing interconnectedness of global supply chains and the heightened risk to personal data as cyberattacks on logistics infrastructure become more common. For consumers, it serves as a reminder to watch for unusual activity, especially if they have recently placed orders through any of the affected companies.
via TechCrunch
