Ceva Logistics, a France-based global shipping company, confirmed a cyberattack that compromised personal data of customers belonging to multiple companies using its European warehouses. The breach, which began on July 29, affected eight logistics facilities across Europe, disrupting shipping operations and exposing names, addresses, phone numbers, and email addresses. Dutch online retailer Bol disclosed that hackers accessed its warehousing partner Ceva's systems, putting customer data at risk and leading to order delays and cancellations. De Bijenkorf, Ajax football club, ING bank, eyewear brand Ace & Tate, and video game company Valve also reported that customer shipping information was stolen. Valve informed recent Steam hardware buyers on August 7 that their data had been taken, noting Ceva retains delivery details for 90 days after purchase. Ceva stated it activated cybersecurity protocols on August 1 and is investigating with authorities, though spokesperson Ryan Fisher declined to confirm how much data was stolen or whether a ransom was demanded. The company said only the eight European warehouses were impacted and other global operations remain unaffected. Ceva's website experienced outages as the incident unfolded.
The breach reveals how deeply third-party logistics providers are embedded in customer data flows, yet operate beyond direct consumer oversight. When major brands entrust shipping partners with sensitive data, customers have no control over the security standards protecting it. Ceva has not disclosed whether encryption was used or if hackers accessed active accounts, leaving affected users in the dark.
Editorial note: AI-assisted opinion, not established fact. Full disclaimer →