A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Ceva Logistics was hit by a cyberattack that began July 29, per FreightWaves, disrupting at least eight European warehouses used for shipping goods across the continent while leaving the rest of its global operations unaffected.
- Ceva confirmed to affected customers on August 1 that the intrusion impacted part of its European contract logistics operations; the France-headquartered firm reported $18.3 billion in 2025 revenue and operates over 1,000 warehouses worldwide.
- Dutch online retailer Bol warned that hackers accessed Ceva's systems to reach its customers' data and expects shipping delays plus some order cancellations as a result.
- Valve alerted Steam hardware buyers on August 7 that their shipping data was exposed, noting that Ceva retains delivery information for 90 days following each order.
- Dutch data protection authority spokesperson Mark Schenkel said the agency has received data breach reports from 10 organizations tied to the incident, with Ajax, ING, Ace & Tate, and De Bijenkorf among the affected parties.
- Ceva declined to answer whether it knows how much personal data was taken or whether hackers issued a ransom demand, while authorities in the Netherlands investigate.
Why it matters: A single breach at one logistics vendor has already triggered 10 regulatory breach filings in the Netherlands and exposed personal data across retail, banking, sports, and gaming — illustrating how consolidated shipping partners become force multipliers for cybercriminals, and Ceva's refusal to disclose ransom details leaves customers and partners without a clear threat picture.
Ask SkimNews




