A cyberattack on Ceva Logistics clearly demonstrates how dependent modern supply chains have become not only on transportation but also on data. According to the logistics company, eight warehouse locations in Europe are affected. Other Ceva systems and business divisions are said to be unaffected.
Ceva informed affected customers on August 1st about the incident. Subsequently, some clients experienced delays in orders, returns, and deliveries. Dutch online retailer Bol even had to temporarily remove goods from an affected warehouse from its online offering and could not accept new goods there.
Even more concerning is the possible or partially confirmed loss of customer data. Affected companies operate in completely different industries. Those mentioned include Bol, department store De Bijenkorf, Ajax Amsterdam, bank ING, eyewear retailer Ace & Tate, and Valve, the operator of the Steam gaming platform.
For Valve, it is now relatively clear what happened. Ceva handles Steam hardware shipping in Europe. According to Valve, attackers were able to view and copy names, delivery addresses, phone numbers, email addresses, and information about ordered products. Payment data, passwords, and Steam access credentials were not stored at Ceva and were therefore not affected, according to Valve.
The extent of the breach at other Ceva customers has not yet been fully clarified. The Dutch data protection authority had already received reports from ten organizations related to the incident by August 10th.
This case is of interest to the logistics industry because Ceva is not a small niche provider. The company belongs to the CMA CGM Group, generated revenue of $18.3 billion in 2025, and operates approximately 1,100 warehouse locations worldwide.
