Cyberattack on logistics giant CEVA delivers customer data into the wrong hands
A cyberattack on French logistics giant CEVA has disrupted operations at eight European warehouses and exposed customer data belonging to a growing list of major clients, including Valve, Bol, ING and Ajax. The breach occurred between 29 July and 1 August 2026 and affected parts of CEVA's contract logistics business, though its air, ocean, ground and rail transport operations continued unaffected. The incident matters because it highlights how a single supply-chain compromise can ripple across unrelated industries, from gaming to banking to retail, exposing customers who had no direct relationship with CEVA itself.
Valve, which uses CEVA to ship Steam hardware in Europe, warned customers that attackers likely stole names, addresses, phone numbers, email addresses and order details, though payment information and passwords were not exposed as CEVA never held them; the company cautioned that the stolen data could fuel convincing phishing attempts. Dutch retailer Bol halted data exchanges with CEVA and took products offline at one affected fulfilment centre, with some orders delayed as of 6 August, while department store De Bijenkorf, football club Ajax, banking giant ING and eyewear maker Ace & Tate reportedly had shipping details exposed too. CEVA, which operates over 1,000 warehouses worldwide and generated $18.3 billion in revenue last year, has not disclosed how the attackers gained access, how much data was stolen, or how many people were affected, and did not respond to requests for comment.
- CEVA logistics hack exposed customer data across multiple major clients
- Valve, Bol, ING, Ajax and others affected by breach
- CEVA hasn't disclosed attack method, scale, or number affected