A data breach at shipping giant Ceva Logistics impacts banks, retailers, and Steam gamers
Global shipping giant Ceva Logistics has suffered a cyberattack, causing personal data leaks that ripple across retail partners like Bol and gaming giant Valve.

Stock photo for illustration only, not from the actual event
- Global shipping and logistics giant Ceva Logistics hit by a cyberattack
- Hack began on July 29, affecting at least eight warehouses across Europe
- Personal data stolen from partner companies including Bol and Valve (Steam)
- Dutch data protection authority receives breach reports from 10 organizations
Ceva Logistics, one of the world's largest shipping and logistics enterprises, has fallen victim to a major cyberattack. Several partner companies relying on Ceva to ship products to customers reported that their personal data was also compromised during the breach.
The company disclosed to TechCrunch that the cyberattack is impacting at least eight warehouses across Europe used for continental shipping. Industry news publication FreightWaves reported that the hack commenced on July 29, triggering shipping delays for numerous goods stored within the affected facilities.
Headquartered in France, Ceva is a global logistics leader trusted by corporations worldwide to transport goods from assembly lines to consumer doorsteps. Generating $18.3 billion in revenue in 2025, the firm operates over a thousand warehouses globally. In recent years, logistics giants have emerged as prime targets for cybercriminals seeking entry points to hijack trucks and containers for real-world criminal syndicates.
The fallout has quickly spread to Dutch online retail giant Bol, which announced on its website that hackers breached the systems of its warehousing partner, Ceva, warning that customer data may have been compromised. Bol added that it anticipates delivery delays and potential cancellations of certain customer orders.
<
Stock photo for illustration only, not from the actual event
In the gaming sector, video game titan Valve informed customers on August 7 that data had been exfiltrated from Ceva's systems. Valve alerted users who recently purchased Steam hardware that their personal information was exposed. In a notification posted to Reddit, Valve explained that Ceva stores shipping and delivery information for 90 days following an order. Doug Lombardi, a Valve spokesperson, did not respond to requests for comment.
Attacks on major global logistics providers highlight critical vulnerabilities in modern supply chain ecosystems. Because warehousing networks deeply integrate with hundreds of third-party vendors, cybercriminals increasingly exploit them as vector points to compromise downstream retail and consumer data, creating cascading operational disruptions far beyond the primary target.
Ceva confirmed in a formal statement that it was experiencing a cyberattack. Ryan Fisher, a spokesperson for Ceva, declined to answer inquiries regarding the total volume of personal data stolen or whether hackers had made any ransom demands. Ceva noted that several affected applications have been restored and that it is cooperating with authorities.
Authorities in the Netherlands have launched an investigation into the incident. Mark Schenkel, a spokesperson for the Dutch data protection authority, confirmed that the agency has received data breach notifications from 10 distinct organizations linked to the breach.
Source: TechCrunch
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment