French shipping giant Ceva Logistics has suffered a major cyberattack and data breach starting on 29 July across eight European warehouses, leaking the personal data of retail, banking, and gaming customers. Several global companies that rely on the logistics firm to deliver orders have confirmed that their customers’ sensitive information was compromised during the security incident.
European Warehouses Paralysed by Cyberattack
The cyberattack has directly disrupted operations at eight key contract logistics warehouses across Europe, causing widespread shipping delays. Industry news outlet FreightWaves reported that the security breach began in late July, halting the movement of goods and backlogging supply chains across the continent.
Headquartered in France, Ceva Logistics is an international powerhouse in the supply chain sector, generating $18.3 billion in revenue in 2025 and managing over a thousand warehouses worldwide. Cybercriminals are increasingly targeting supply chain and transport firms to hijack shipments and divert physical cargo into the hands of organised criminal gangs.
High-Profile Brands and Retailers Suffer Data Leaks
In addition to physical disruptions, the hackers successfully breached Ceva’s digital systems, stealing extensive databases of customer information. Compromised data includes full names, delivery addresses, telephone numbers, and email addresses used to process online orders.
Major Dutch Retailers Warn Customers
Dutch e-commerce giant Bol published an alert on its website, warning users that hackers had accessed the systems of its logistics partner, Ceva. The company also stated that consumers should prepare for shipping delays and potential order cancellations as a direct consequence of the hack.
Similarly, luxury department store chain De Bijenkorf confirmed that its customer data had been stolen, leading to delivery delays, according to reports by local media. Other major organisations, including the football club Ajax, banking multinational ING, and eyewear retailer Ace & Tate, also confirmed that their customers’ shipping details were caught up in the breach.
Steam Hardware Customers Caught in the Crosshairs
Gaming giant Valve notified customers on 7 August that their personal details had been compromised through Ceva’s systems. The breach affected individuals who recently purchased Steam hardware, such as the Steam Deck.
In a notification letter shared by affected users on Reddit, Valve explained that Ceva retains customer delivery information for a 90-day period following shipment. Valve spokesperson Doug Lombardi did not return requests for comment regarding the security incident.
Ceva Logistics Responds to the Intrusion
Ceva Logistics officially confirmed the cyberattack in a statement, noting that security protocols were activated immediately upon detection.
“On Aug. 1, CEVA Logistics confirmed to affected customers that a cyber intrusion was impacting part of its European contract logistics operations. As soon as the incident was identified, CEVA’s cybersecurity teams immediately activated its security protocols and launched a thorough investigation, which is still ongoing,” the company stated. “The operational impact is limited to eight warehouses. No other CEVA systems globally were affected, and all other operations continue without incident.”
Ceva spokesperson Ryan Fisher declined to answer specific questions regarding the volume of stolen data or whether the attackers had made a ransom demand. While the company stated that some affected digital services and applications have been restored, Ceva’s main website remained offline or failed to load correctly at the time of publication.
Privacy regulators are now monitoring the situation closely. Mark Schenkel, a spokesperson for the Dutch Data Protection Authority, confirmed that the regulatory body has already received formal data breach notifications from 10 different organisations linked to the Ceva incident.
