Ceva Logistics Breach: One Supplier Intrusion, Eight Disrupted Warehouses, Twelve Breach Notifications Across European Retail, Banking and Sport
On August 1, 2026, Ceva Logistics confirmed to affected customers that a cyber intrusion was impacting part of its European contract logistics operations. According to transportation news outlet FreightWaves, the attack began on July 29. Ceva — a France-headquartered subsidiary of shipping group CMA CGM with roughly 110,000 employees and more than 1,700 facilities worldwide, and $18.3 billion in revenue in 2025 (TechCrunch) — stated that the operational impact was limited to eight European warehouses, and that its air, ocean, ground and rail transportation management operations continued without disruption.
The cascade arrived through Ceva’s clients. Dutch e-commerce platform Bol told customers that attackers gained access to two Ceva systems used to process orders from one of its distribution centres, and that data held in those systems — names, addresses, postal codes, telephone numbers, email addresses, order numbers, tracking information, purchase details and even messages attached to gift cards — may have been viewed or copied. Bol suspended data exchanges with Ceva as a precaution and took the assortment stored at the affected location offline. De Bijenkorf, Ace & Tate, Amsterdam football club Ajax and ING — for customers who ordered physical items through its points programme, with no payment data leaked according to the bank — confirmed exposure in the following days.
The most detailed account came from Valve. On August 10 it began notifying European buyers of Steam hardware that their name, street address, postal code, city, country, telephone number, email address, and the type and price of hardware ordered may have been compromised, because Ceva handles Valve’s European shipments and can retain those delivery records for up to 90 days after an order. Payment information, passwords and Steam Guard codes were not exposed — Ceva never had them. Valve said it could not determine precisely which records the attackers obtained, was pressing Ceva for the full scope, was notifying the data protection authorities in affected countries, and warned customers to expect convincing delivery-themed phishing that quotes their own address back at them.
On August 11, the Dutch data protection authority (Autoriteit Persoonsgegevens) confirmed, following reporting by AD, that twelve companies had filed breach notifications linked to the Ceva incident. Ceva itself has made no public disclosure. There is no public attribution, and it remains unconfirmed whether ransomware was deployed or a ransom demanded. Dutch media additionally reported a dark-web listing of customer data connected to the incident; this listing is unconfirmed, and Ceva reportedly attributes it to an earlier 2025 incident — treat that claim as unverified on both sides.
1. What Happened
1. On August 1, 2026, Ceva Logistics confirmed to affected customers that a cyber intrusion was impacting part of its European contract logistics operations; FreightWaves, citing a source familiar with the investigation, reports the attack began on July 29 (Ceva statement to TechCrunch; FreightWaves, August 10–11, 2026).
2. Eight European warehouses were disrupted, delaying or cancelling retail orders; no Ceva systems beyond those warehouses were affected, and air, ocean, ground and rail transportation management operations continued (Ceva statement; FreightWaves via The Record, August 10–11, 2026).
3. Ceva informed Bol on August 1 that attackers accessed two order-processing systems serving one Bol distribution centre; customer and shipment data may have been viewed or copied, and Bol suspended data exchanges with Ceva pending the investigation (Bol customer notification via security.nl / The Record, August 2026).
4. Valve began notifying European Steam hardware customers on August 10 that delivery data — retained by Ceva for up to 90 days after an order — may have been compromised, and said it is notifying data protection authorities in affected countries (Valve notification via The Record / The Register, August 10–11, 2026).
5. On August 11, the Dutch DPA (Autoriteit Persoonsgegevens) confirmed that twelve companies had filed breach notifications related to the Ceva incident; confirmed affected brands include Bol, De Bijenkorf, Ace & Tate, Ajax, ING and Valve (AP via ANP / AD, August 11, 2026; NOS; The Register).
2. Business Impact
[CONFIRMED] Eight Ceva warehouses across Europe disrupted, with customer orders delayed or cancelled and stock at affected locations taken offline for sale and inbound receiving (Ceva statement to TechCrunch; Bol via TechRadar, August 10–11, 2026).
[CONFIRMED] Twelve companies filed personal-data breach notifications with the Dutch Autoriteit Persoonsgegevens over the incident (AP confirmation via ANP / AD, August 11, 2026).
[CONFIRMED] Bol customer data possibly viewed or copied: names, addresses, postal codes, telephone numbers, email addresses, order numbers, tracking information, purchase details and gift-card messages (Bol customer notification via The Record, August 11, 2026).
[CONFIRMED] European Steam hardware buyers’ names, full addresses, contact details and hardware type and price potentially compromised; payment information, passwords and Steam Guard codes were not exposed because Ceva does not hold them (Valve notification via The Record / The Register, August 10–11, 2026).
[CONFIRMED] ING customers who ordered physical items through its points programme are affected; the bank states no payment data was leaked, while exposure of address and contact data remained under investigation (NOS, August 2026; The Register, August 11, 2026).
3. Likely Root Cause
The intrusion vector, malware family and attacker identity have not been publicly disclosed; there is no attribution, and it is unconfirmed whether ransomware was deployed or an extortion demand was made.
Source: The Record, August 11, 2026
Attackers gained access to order-processing systems inside Ceva’s contract-logistics IT environment — two systems serving a single Bol distribution centre are confirmed — rather than to any client’s own network.
Source: Bol customer notification via The Record, August 2026
Customer data from many brands was concentrated in shared supplier systems and retained after fulfilment — up to 90 days post-order in Valve’s case — enlarging the exposure window well beyond operational need.
Source: Valve notification via The Record, August 10, 2026; concentration assessed from breach scope reporting
Affected controllers depended entirely on Ceva for breach facts: Valve stated it could not determine which records were obtained and notified customers on a reasonable-assumption basis — indicating no contractual mechanism delivered timely, field-level scoping.
Assessed from Valve notification via The Record, August 11, 2026
4. Control Failures
[CF-1] 🔗 THIRD PARTY A single logistics provider held live customer and shipment data for many brands simultaneously, without supplier assurance, segmentation or contractual controls commensurate with that concentration — one intrusion produced twelve controllers’ breach notifications.
[CF-2] 📋 PROCESS No enforced data minimisation or retention limits at the supplier: delivery records persisted up to 90 days after an order, and non-essential fields such as gift-card messages transited and sat in logistics systems.
[CF-3] ⚙️ TECHNOLOGY Assessed absence of effective intrusion and exfiltration detection in the order-processing environment: the attack began around July 29, clients were informed August 1, and the scope of what was taken remained undetermined weeks later.
[CF-4] 📋 PROCESS No incident-response interlock adequate for controllers’ GDPR duties: affected brands could not obtain field-level scoping from their processor and had to notify customers on assumptions, while Ceva made no public disclosure.
[CF-5] 👥 PEOPLE End customers of at least twelve organisations became targets for delivery-themed phishing armed with accurate names, addresses and order details — the human follow-on attack surface Valve explicitly warned about in its notification.
5. Recommendations
5A — Organisational & Technical Controls
↳ CF-1 Impose contractual supplier security with audit rights and per-client segregation (NIS2 Article 21(2)(d) — supply chain security; ISO 27001:2022 Annex A 5.19/5.20; GDPR Article 28(3))
Make holding your customer data conditional: Article 28(3) processing terms with audit rights (Art. 28(3)(h)), logical segregation of each client’s order data so one intrusion cannot traverse brands, a 24-hour contractual breach-notification SLA, and annual independent evidence (penetration test report or SOC 2 Type II) — not a questionnaire.
↳ CF-2 Enforce minimisation and retention limits inside the supplier’s systems (GDPR Article 5(1)(c) and 5(1)(e); Article 28(3)(g); CIS Controls v8.1 — Safeguard 3.4)
Contractually purge delivery records within days of confirmed delivery rather than a standing 90-day window; strip non-essential fields (gift-card messages, order price where not needed for fulfilment) from logistics data feeds at the integration layer; require automated deletion attestations per cycle. Every retained field and day is blast radius.
↳ CF-3 Require exfiltration detection and egress monitoring on order-processing systems (CIS Controls v8.1 — Control 13; NIST SP 800-53 Rev. 5 — SI-4, SC-7; ISO 27001:2022 Annex A 8.12, 8.16)
Suppliers processing your customer data must run DLP and egress-anomaly alerting on the systems that hold it, with alert thresholds on bulk reads and out-of-pattern queries, and grant you the contractual right to receive security alerts affecting your data sets. Deliver the user-facing rules below (5B) to your customer base as a standing briefing whenever a supplier incident is confirmed.
↳ CF-4 Build an incident-response interlock that can feed your 72-hour clock (GDPR Article 33(1)–(2) and Article 34; NIS2 Article 23; ISO 27001:2022 Annex A 5.20)
Define in the processing agreement the exact artefact set the processor must deliver within 48 hours of discovery — affected record counts, field-level data inventory, access timeline — and rehearse it: a joint incident-response playbook and an annual tabletop with every critical fulfilment supplier. Valve’s reasonable-assumption notification is what its absence looks like.
5B — For the Online Shopper
↳ CF-5 · Plain-language rules for customers of the affected brands — and anyone who buys online. Umbrella citation: NIS2 Article 21(2)(g) — cyber hygiene and awareness; ISO 27001:2022 Annex A 6.3.
1. Treat every delivery message as unverified — even one that knows your name and address.
Criminals now hold exactly that information. A message quoting your own address back to you proves nothing about who sent it.
2. Never pay a “small fee” from a link in a message.
Real carriers and shops do not collect customs charges or redelivery fees through links in texts or emails. That request is the scam itself.
3. Check your order where you placed it.
Open the shop’s official app or type its web address yourself to see your order status. Do not tap links in delivery messages, however genuine they look.
4. Never sign in from a delivery message.
No legitimate delivery update asks you to log in to “verify” an order. A login page reached from a message is how passwords get stolen.
5. Report it, then delete it.
Forward suspicious messages to the brand’s official phishing address or your national anti-fraud service, then delete. Reporting protects the next person.
Screenshot this box and forward it. It is written for the person waiting for a parcel — no jargon required.
6. Regulatory Relevance
GDPR Article 28(3) (processor contract terms); Articles 33(1)–(2) & 34 (breach notification); Article 5(1)(c), (e), (f); Article 32
The operative regime of this case. Twelve controllers filed with the Dutch AP within days — the notification duty sat with the brands, not the logistics provider, while Article 33(2) obliged Ceva as processor to notify its controllers without undue delay. The 90-day retention of delivery data engages storage limitation (Art. 5(1)(e)); gift-card messages in logistics feeds engage data minimisation (Art. 5(1)(c)).
NIS2 Annex I — transport sector; Article 21(2)(d) — supply chain security; Article 23 — 24h early warning / 72h notification
Large logistics operators fall within NIS2’s transport sector, and every affected retailer’s supply-chain risk management obligations are engaged. Intersection to flag: France (Ceva’s home jurisdiction) and the Netherlands (where the impact concentrated) were both reported still in NIS2 transposition procedure as of Q2 2026 — so the EU-wide lever that actually operated here was GDPR, not NIS2. Verify transposition status per jurisdiction before client advice.
DORA Articles 28–30 — ICT third-party risk (scope boundary)
ING’s exposure arrived through a logistics provider, not an ICT service provider — a channel DORA’s third-party oversight regime does not capture. The lesson for financial entities: third-party data risk is wider than DORA’s ICT perimeter and must be governed through GDPR Article 28 terms and the EBA Guidelines on outsourcing arrangements. [KB UPDATE NEEDED] EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02) — scope: outsourcing governance for EU banks and payment institutions; relevance: non-ICT critical supplier oversight.
ISO 27001:2022 Annex A 5.19–5.22 (supplier relationships), 5.14 (information transfer), 8.12 (data leakage prevention), 8.16 (monitoring activities)
Supplier security governance, secured information transfer to logistics partners, and leakage prevention and monitoring on systems holding customer data are direct control expectations; a certified ISMS sharing customer data with an unassessed fulfilment provider carries nonconformity risk across 5.19–5.22.
CIS Controls v8.1 Control 15 (service provider management), Control 3 — esp. Safeguard 3.4 (data retention), Control 13 (network monitoring and defense)
Service-provider inventory and assessment, enforced retention standards, and monitoring on data-holding systems are the safeguards most directly engaged when the breach happens on a supplier’s network but the data — and the notification duty — are yours.
7. How SEG Can Help
↳ CF-1 / CF-4 💡 Third-Party Risk Assessment
SEG assesses the security posture of fulfilment and logistics providers before they hold your customer data — access controls, segmentation, detection capability and the contractual terms (audit rights, notification SLAs, IR artefact sets) that determine whether you can meet your own 72-hour clock when their network is breached.
↳ CF-2 💡 vCISO & SaaS Configuration Review
SEG’s vCISO service builds the data-classification, minimisation and retention governance for supplier data flows — defining which fields leave your environment, for how long, and with what deletion evidence — and reviews the integrations that carry them.
↳ CF-3 💡 Penetration Testing & Vulnerability Management
SEG simulates the attack paths that matter in shared-supplier environments — lateral movement between client data sets and bulk-exfiltration channels — validating that segmentation and egress monitoring hold under adversary pressure, not just on paper.
↳ CF-5 💡 Security Awareness Training
SEG delivers customer- and employee-facing awareness programmes for exactly the follow-on wave this breach created: delivery-themed phishing armed with accurate personal data. Section 5B above is what SEG training material looks like — ready to forward.
🎯 Strategic Signal
The Ceva incident marks where third-party risk is heading in 2026: away from the ICT vendor every framework already watches, toward the operational supplier — the warehouse, the shipper, the fulfilment partner — that regulatory regimes like DORA barely see. Blast radius is no longer defined by your own perimeter but by two variables you set contractually and then forget: which data fields you send a supplier, and how long they keep them. One intrusion, twelve breach notifications — the organisations that fare best will be those that treat every data flow to a supplier as a standing liability to be minimised, not a solved integration.
💬 SEG Expert View — Denys Leontiev, Senior Security Expert
Look at what the attacker did not have to do: they never touched Bol, never touched Valve, never touched ING. Entry into a logistics order-processing environment was enough to compromise the customers of at least twelve organisations at once. From a threat perspective, order-management systems are a perfect target — fresh, structured, monetisable personal data, refreshed daily, and defended to the supplier’s standard, not yours. Two technical realities follow. First, your detection perimeter ends where your supplier’s begins: if they cannot see an intrusion in the systems holding your data, you learn about your own breach from a notification letter, weeks later, with the scope still unknown — exactly Valve’s position. Second, every field you transmit and every day it is retained is attack surface you no longer control; ninety days of delivery records and gift-card messages sitting in a warehouse system served no one but the attacker. Our advice is concrete: segregate your data per client at the supplier, demand egress monitoring on the systems that hold it, cut retention to operational need, and rehearse the incident handover before you need it. The NIS2 Directive makes supply-chain security an explicit obligation — but the phishing wave now hitting these customers will not wait for transposition deadlines.
📖 Sources
• The Record — Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe — August 11, 2026
• TechCrunch — A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond — August 10, 2026
• The Register — Cyberattack on logistics giant CEVA delivers customer data into the wrong hands — August 11, 2026
• ANP via Accountant.nl — Twaalf meldingen bij Autoriteit Persoonsgegevens na datalek CEVA — August 12, 2026
• NOS — Ook Ajax en brillenketen Ace & Tate getroffen door datalek — August 2026
📢 Need help securing your organisation? Contact SEG for expert cybersecurity solutions tailored to your needs.