Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe
A cyberattack on global freight company Ceva Logistics has reportedly disrupted shipments for major 2026-8-11 16:3:59 Author: therecord.media(查看原文) 阅读量:2 收藏

A cyberattack on global freight company Ceva Logistics has reportedly disrupted shipments for major European retailers and potentially exposed customer data belonging to users of a popular video game platform.

Ceva has not publicly disclosed the attack and did not respond to a request for comment. However, according to media reports, the company notified corporate clients earlier this month that a cyber intrusion was affecting part of its contract logistics business.

The incident reportedly disrupted operations at eight warehouses in Europe, causing shipping delays for retailers whose inventory was stored at the affected facilities.

Companies reported to have been affected include Dutch e-commerce giant Bol, luxury department store De Bijenkorf, eyewear company Ace & Tate and Amsterdam football club Ajax, as well as Steam’s hardware business in Europe. 

The full scope of the breach remains unclear, including the locations of the eight affected warehouses. Ceva has not said who was behind the attack or whether the hackers demanded a ransom.

Retail victims

Ceva informed Bol, the e-commerce platform, about the cyberattack on August 1, according to a notification Bol sent to affected customers that was subsequently reported by Dutch media.

The company said an investigation found that cybercriminals had gained access to two Ceva systems used to process orders from one of Bol's distribution centers and did not affect the company's own systems.

Products stored at affected locations were temporarily taken offline, while some customer orders were delayed or canceled. Bol also suspended data exchanges with Ceva as a precaution, saying they would resume only when it was safe to do so.

The compromised Ceva systems reportedly contained customer and shipment information. Bol told affected customers that information stored in those systems at the time of the attack may have been viewed or copied by unauthorized parties.

Potentially exposed data included names, addresses, postal codes, telephone numbers, email addresses, order numbers, tracking information and purchase details. Some records could also contain messages attached to gift cards.

Bol said Ceva took steps to stop the unauthorized access after discovering the breach and brought in outside cybersecurity specialists to investigate.

Other Ceva customers reportedly affected include Ajax, the Amsterdam football club for which the logistics company handles merchandise and online orders, and Dutch eyewear company Ace & Tate.

Ceva’s Dutch operations also serve other major brands. The company says on its website that it operates eight e-commerce locations in the Netherlands and identifies Bol, Zalando and De Bijenkorf among the customers served by its operations there. De Bijenkorf warned customers last week that a cyberattack on one of its logistics providers had caused delays to orders, returns and refunds and could have exposed customer data.

FreightWaves, a transportation news and data provider, reported, citing a source familiar with the investigation, that no Ceva systems beyond the eight warehouses were affected. The company's air, ocean, ground and rail transportation management operations continued without disruption, according to the report.

Steam customers warned

One of the most detailed accounts of the breach has come from Valve, the U.S. video game company behind Steam gaming platform.

Valve began notifying European customers on Monday that information associated with purchases of physical Steam hardware may have been compromised because Ceva handles the company's shipments in Europe.

Ceva receives customer delivery information from Valve and can retain those records for up to 90 days after an order, according to the notification.

Valve said it could not determine precisely which records the attackers obtained and therefore notified customers whose information it could reasonably assume may have been affected.

The potentially compromised information includes customers' names, street addresses, postal codes, cities, countries, telephone numbers and email addresses, as well as the type and price of Steam hardware they ordered.

“We're pressing Ceva for the full scope of what was taken and how, and we are in the process of notifying the data protection authorities in the countries affected,” Valve said.

There has been no public attribution for the attack so far, and it remains unclear whether ransomware was deployed or whether the hackers made an extortion demand.

Ceva Logistics, headquartered in France, is one of the world's largest logistics and supply chain companies. It employs about 110,000 people and operates more than 1,700 facilities worldwide.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.


文章来源: https://therecord.media/ceva-logistics-cyberattack-bol-steam-debijenkorf-ace-tate
如有侵权请联系:admin#unsafe.sh