BTC$63,057+0.34% LTC$44.05+1.12% XMR$412.08+4.33%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Aug 11, 2026 · 4 min read · Original story

Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe

Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe
Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe

A cyberattack on global freight company Ceva Logistics has reportedly disrupted shipments for major European retailers and potentially exposed customer data belonging to users of a popular video game platform.

Ceva has not publicly disclosed the attack and did not respond to a request for comment. However, according to media reports, the company notified corporate clients earlier this month that a cyber intrusion was affecting part of its contract logistics business.

The incident reportedly disrupted operations at eight warehouses in Europe, causing shipping delays for retailers whose inventory was stored at the affected facilities.

Companies reported to have been affected include Dutch e-commerce giant Bol, luxury department store De Bijenkorf, eyewear company Ace & Tate and Amsterdam football club Ajax, as well as Steam’s hardware business in Europe.

The full scope of the breach remains unclear, including the locations of the eight affected warehouses. Ceva has not said who was behind the attack or whether the hackers demanded a ransom.

Retail victims

Ceva informed Bol, the e-commerce platform, about the cyberattack on August 1, according to a notification Bol sent to affected customers that was subsequently reported by Dutch media.

The company said an investigation found that cybercriminals had gained access to two Ceva systems used to process orders from one of Bol's distribution centers and did not affect the company's own systems.

Products stored at affected locations were temporarily taken offline, while some customer orders were delayed or canceled. Bol also suspended data exchanges with Ceva as a precaution, saying they would resume only when it was safe to do so.

The compromised Ceva systems reportedly contained customer and shipment information. Bol told affected customers that information stored in those systems at the time of the attack may have been viewed or copied by unauthorized parties.

Potentially exposed data included names, addresses, postal codes, telephone numbers, email addresses, order numbers, tracking information and purchase details. Some records could also contain messages attached to gift cards.

Bol said Ceva took steps to stop the unauthorized access after discovering the breach and brought in outside cybersecurity specialists to investigate.

Other Ceva customers reportedly affected include Ajax, the Amsterdam football club for which the logistics company handles merchandise and online orders, and Dutch eyewear company Ace & Tate.

Ceva’s Dutch operations also serve other major brands. The company says on its website that it operates eight e-commerce locations in the Netherlands and identifies Bol, Zalando and De Bijenkorf among the customers served by its operations there. De Bijenkorf warned customers last week that a cyberattack on one of its logistics providers had caused delays to orders, returns and refunds and could have exposed customer data.

FreightWaves, a transportation news and data provider, reported, citing a source familiar with the investigation, that no Ceva systems beyond the eight warehouses were affected. The company's air, ocean, ground and rail transportation management operations continued without disruption, according to the report.

Steam customers warned

One of the most detailed accounts of the breach has come from Valve, the U.S. video game company behind Steam gaming platform.

Valve began notifying European customers on Monday that information associated with purchases of physical Steam hardware may have been compromised because Ceva handles the company's shipments in Europe.

Ceva receives customer delivery information from Valve and can retain those records for up to 90 days after an order, according to the notification.

Valve said it could not determine precisely which records the attackers obtained and therefore notified customers whose information it could reasonably assume may have been affected.

The potentially compromised information includes customers' names, street addresses, postal codes, cities, countries, telephone numbers and email addresses, as well as the type and price of Steam hardware they ordered.

“We're pressing Ceva for the full scope of what was taken and how, and we are in the process of notifying the data protection authorities in the countries affected,” Valve said.

There has been no public attribution for the attack so far, and it remains unclear whether ransomware was deployed or whether the hackers made an extortion demand.

Ceva Logistics, headquartered in France, is one of the world's largest logistics and supply chain companies. It employs about 110,000 people and operates more than 1,700 facilities worldwide.

References in this story

  1. Cyberattack on Ceva Logistics warehouses in Europe impacts retailers www.freightwaves.com Ceva Logistics is scrambling to patch a cybersecurity breach and fully restore operations at eight European warehouses that fulfill orders for e-commerce retailers.
  2. Bol waarschuwt voor datalek - Security.NL www.security.nl
  3. Ook Ajax en brillenketen Ace & Tate getroffen door datalek nos.nl Er is nog veel onduidelijk over de omvang van het datalek. Er kan niet worden uitgesloten dat er persoonsgegevens zijn gelekt.
  4. Dutch retailer De Bijenkorf warns customer data may be exposed after cyber incident therecord.media Amsterdam-based luxury goods chain De Bijenkorf is the latest retailer to announce a cyber incident involving a third-party logistics provider.
  5. Steam Hardware Updates (@HardwareSteam) on X x.com STEAM HARDWARE UPDATE Between July 29 and August 1, a cyber attack unfortunately hit Valve’s logistics partner, CEVA Logistics, affecting Steam Hardware customers in Europe (for Steam Controller and Steam Machine) This…
  6. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  7. Daryna Antoniuk (@darynant.bsky.social) bsky.app Cybersecurity Reporter at Recorded Future News. Ex at The Kyiv Independent/Forbes/The Kyiv Post 📍Kyiv, Ukraine

Guides related to this story

← Back to all news