# Cyber Attack on Ceva Logistics Impacts Retailers, ING Customers, and Steam Buyers

**Category:** Companies  |  **Source:** Frachtportal Redaktion  |  **Published:** 2026-08-12  |  **Updated:** 2026-09-12

**Tags:** Ceva Logistics, Cybersecurity, CMA CGM, Cyberangriff, Datenleck, Kontraktlogistik, Datenschutz, Niederlande, Lieferverzögerung, Logistik News, Transport News, Fracht News, Speditions News, Supply Chain News, Zoll News, Frachtportal News, Seefracht, Schienentransport, Digitalisierung

> Cyber attack on Ceva Logistics: Eight warehouses affected, shipments delayed, and customer data from multiple clients potentially or confirmed to have been compromised.

---

A cyberattack on Ceva Logistics clearly demonstrates how dependent modern supply chains have become not only on transportation but also on data. According to the logistics company, eight warehouse locations in Europe are affected. Other Ceva systems and business divisions are said to be unaffected.

Ceva informed affected customers on August 1st about the incident. Subsequently, some clients experienced delays in orders, returns, and deliveries. Dutch online retailer Bol even had to temporarily remove goods from an affected warehouse from its online offering and could not accept new goods there.

Even more concerning is the possible or partially confirmed loss of customer data. Affected companies operate in completely different industries. Those mentioned include Bol, department store De Bijenkorf, Ajax Amsterdam, bank ING, eyewear retailer Ace & Tate, and Valve, the operator of the Steam gaming platform.

For Valve, it is now relatively clear what happened. Ceva handles Steam hardware shipping in Europe. According to Valve, attackers were able to view and copy names, delivery addresses, phone numbers, email addresses, and information about ordered products. Payment data, passwords, and Steam access credentials were not stored at Ceva and were therefore not affected, according to Valve.

The extent of the breach at other Ceva customers has not yet been fully clarified. The Dutch data protection authority had already received reports from ten organizations related to the incident by August 10th.

This case is of interest to the logistics industry because Ceva is not a small niche provider. The company belongs to the CMA CGM Group, generated revenue of $18.3 billion in 2025, and operates approximately 1,100 warehouse locations worldwide.

---

There's an important lesson here for freight forwarders and shippers: A logistics service provider today receives far more data than just weight, number of packages, and delivery address.

In warehouse, fulfillment, and e-commerce processes, customer names, addresses, phone numbers, email addresses, article information, and sometimes additional order data flow through the logistics provider's systems.

This automatically makes the 3PL service provider – the external logistics partner – part of the customer's IT security chain.

For shippers, this means: When selecting and qualifying a logistics partner, not only price, warehouse space, lead times, and on-time delivery should be checked. IT security, disaster recovery plans, backup systems, and the question of how quickly a service provider can resume shipments after a cyberattack are equally important.

For dispatch planning, such an attack can mean something quite straightforward: warehouse is down, orders cannot be released, goods are available, but still cannot be shipped. Add to this backlogs, additional transports, customer complaints, and possibly manual workaround processes.

In short: A cyberattack on a contract logistics provider can stop the supply chain just as quickly today as a strike, a closed port, or a failed warehouse management system.

---

Ceva Logistics confirms a cyberattack on parts of its European contract logistics operations.
According to Ceva, the operational impact is limited to eight warehouse locations.
Affected customers were notified on August 1, 2026.
Valve identifies a possible access period from July 29 to August 1.
For Steam Hardware customers, names, addresses, phone numbers, and email addresses were compromised.
According to Valve, no Steam passwords, Steam Guard codes, or payment information were stored at Ceva.
Bol reported delivery delays, possible cancellations, and restrictions at one fulfillment location.
ING, Ajax Amsterdam, Ace & Tate, and De Bijenkorf are also among the known affected Ceva customers.
The Dutch data protection authority received reports from ten organizations related to the incident by August 10.
Ceva achieved revenue of $18.3 billion in 2025 and operates approximately 1,100 warehouses worldwide.

## Related Entities

### Countries

- [Netherlands](https://www.freight-academy.com/en/information/land/nl)

### Glossary

- [contract logistics](https://www.freight-academy.com/en/glossary/contract-logistics)
- [Warehouse](https://www.freight-academy.com/en/glossary/warehouse-3)
- [Delivery address](https://www.freight-academy.com/en/glossary/delivery-address)
- [Supply chain](https://www.freight-academy.com/en/glossary/supply-chain-2)
- [return](https://www.freight-academy.com/en/glossary/return)
- [Supply Chain](https://www.freight-academy.com/en/glossary/supply-chain)
- [Shipping](https://www.freight-academy.com/en/glossary/shipping)
- [Goods](https://www.freight-academy.com/en/glossary/goods)
- [Contract Logistics Pricing](https://www.freight-academy.com/en/glossary/contract-logistics-pricing)
- [Cyber Freight Risk Management](https://www.freight-academy.com/en/glossary/cyber-freight-risk-management)
- [Warehouse](https://www.freight-academy.com/en/glossary/warehouse)
- [storage location](https://www.freight-academy.com/en/glossary/storage-location-3)
- [3PL warehouse](https://www.freight-academy.com/en/glossary/3pl-warehouse)
- [Cyber crisis plan](https://www.freight-academy.com/en/glossary/cyber-crisis-plan)

---

*Canonical URL: [https://www.freight-academy.com/en/news/cyberangriff-auf-ceva-logistics-trifft-haendler-ing-kunden-und-steam-kaeufer-20260811171040](https://www.freight-academy.com/en/news/cyberangriff-auf-ceva-logistics-trifft-haendler-ing-kunden-und-steam-kaeufer-20260811171040)*

*Markdown mirror: [https://www.freight-academy.com/api/md/news/en/cyberangriff-auf-ceva-logistics-trifft-haendler-ing-kunden-und-steam-kaeufer-20260811171040](https://www.freight-academy.com/api/md/news/en/cyberangriff-auf-ceva-logistics-trifft-haendler-ing-kunden-und-steam-kaeufer-20260811171040)*