A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Ceva Logistics confirmed on Aug. 1 that a cyber intrusion hit part of its European contract logistics operations, with FreightWaves reporting the hack began July 29 and disrupted goods movement at at least eight warehouses across the continent.
- Ceva's $18.3 billion-revenue shipping network — over a thousand warehouses worldwide — stored customer names, home addresses, phone numbers, and email addresses that hackers stole from systems used by multiple retail and banking clients.
- Dutch online retailer Bol warned customers their data may have been taken via Ceva's warehousing systems and said it expects delays and some order cancellations as a result of the incident.
- De Bijenkorf (luxury retail), Ajax (football club), ING (banking), and Ace & Tate (eyeglass maker) all reported that their customers' shipping information was affected by the Ceva breach.
- Valve told Steam hardware buyers on Aug. 7 that data taken from Ceva's systems included their shipping and delivery information, which Ceva retains for 90 days following an order.
- Dutch data protection authority spokesperson Mark Schenkel told TechCrunch the agency has received data breach reports from 10 organizations tied to the incident, as authorities in the Netherlands investigate.
- Ceva spokesperson Ryan Fisher declined to answer questions about how much personal data was taken or whether the company received a ransom demand, though some affected applications have been restored.
Why it matters: One breach at a single logistics vendor cascaded into confirmed data exposures at a retailer, a bank, a sports club, and a gaming platform — ten organizations have already filed Dutch breach reports. Because Ceva retains shipping data for 90 days and serves as the common fulfillment layer for unrelated brands, the incident shows how a single vendor compromise multiplies downstream notification obligations across sectors simultaneously.
Ask SkimNews




