Security2 distinct publishers3 min readUpdated
A logistics contractor's intrusion stopped shipments and exposed customer delivery data at Bol, De Bijenkorf, ING and Valve. None of them were breached themselves.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A logistics contractor's intrusion stopped shipments and exposed customer delivery data at Bol, De Bijenkorf, ING and Valve. None of them were breached themselves.
Ceva Logistics, the French-headquartered contract logistics arm of CMA CGM Group, had eight European warehouses disrupted by an intrusion that began on 29 July, and on 1 August told affected customers that goods held in those sites were not shipping [1][2][3][4]. Impact was then confirmed by Dutch retailers Bol and De Bijenkorf, ING, Ace & Tate, football club Ajax and Valve [5] - none of whose own systems were compromised, which is the whole problem.
The pattern in each downstream disclosure is the same. Bol said the incident involved two systems used to process orders from one of its fulfilment centres, that no Bol systems were affected, and that data of customers whose orders went through that location may have been viewed or copied [6]. De Bijenkorf said the exposure may cover names, addresses, email addresses, phone numbers and online order details, plus entity names and identification numbers for business customers, and explicitly excluded payment details, IBANs, card data, usernames and passwords [7][8]. Valve warned on 10 August that names, home addresses, phone numbers, Steam account email addresses and hardware order details were exposed, with passwords and payment information untouched [9].
The timeline is where the third-party dependency shows its teeth. Malwarebytes puts the attack window at 29 July to 1 August 2026, says Valve learned of it on 7 August and began notifying customers three days later [10][11] - nine days from intrusion to awareness and twelve to customer notice [1]. Bol and De Bijenkorf were reportedly told on 1 August [12], six days before Valve knew anything [2]. One incident, one supplier, and a notification clock that started on a different date for each brand attached to it.
Retention policy sets the blast radius, and the brands did not set it. Ceva holds delivery data for roughly 90 days after shipment, so anyone in Europe who received a Steam Deck, Steam Controller or Steam Machine in the preceding three months could be affected [13]. Valve confirmed the three-month retention when telling customers their delivery information was likely compromised [14]. Neither Valve nor Ceva has said how many records were involved [15], and it remains unclear how the attackers got in or who they were [16].
The consequence is fraud with real details in it. Malwarebytes notes that a scammer holding a genuine order and delivery address can ask by email, text or phone for a small customs or redelivery fee, or for a sign-in to verify an order [17]. Valve's advice to customers is to treat any message referencing a recent Steam hardware order as fake, including ones that quote the address correctly, and it points out that Steam Support never contacts users by email, Steam Chat or Discord [18][19]. For scale on the market these records feed, Malwarebytes says its researchers found more than 7,500 compromised datasets containing over 8.4 billion records on the dark web in the first half of 2026 [20].
This is not Ceva's first incident either: the extortion group Coinbase Cartel claimed two attacks on the company last year [21].
What to watch: whether Ceva publishes an initial access account and a record count, since six notifying brands currently have none; whether the affected-customer list grows beyond the Netherlands, given Ceva runs more than 1,700 facilities across 170 countries [22]; and whether any of the notifying organisations discloses that it knew, before 29 July, how long its fulfilment partner retained shipping data. That last one is the test of whether these plans modelled the dependency or discovered it.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
On 1 August, Ceva notified affected customers of the cyberattack, informing them that goods stored in the disrupted warehouses were not shipping.
On 10 August, Valve warned customers that a cyberattack had exposed names, home addresses, phone numbers, Steam account email addresses and details of hardware orders, including the type and price of the ordered hardware; passwords and payment information were not touched.
Dutch retailers Bol and De Bijenkorf were reportedly told about the same Ceva incident on 1 August and warned their own customers.
Ceva stores delivery data for roughly 90 days after shipment, meaning anyone who received a Steam Deck, Steam Controller or Steam Machine in Europe over the past three months could be affected.
Valve told customers that delivery-related information was likely compromised, that it uses Ceva to ship physical hardware to customers in Europe, and that Ceva retains shipping information for three months, according to multiple Reddit posts cited by SecurityWeek.
Exact numbers are unconfirmed; neither Valve nor Ceva has said how many customer records were involved.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named-company statements, but no scope from the breached vendor
The core facts rest on attributable statements: Bol and De Bijenkorf issued quoted scoping statements, Valve emailed customers with an explicit field list, and dates for the intrusion, discovery and notification are reported consistently across both publishers. Evidence weakens on the decisive questions — Ceva did not respond to SecurityWeek, no record count exists, intrusion vector and attribution are unknown, and part of Valve's position reached SecurityWeek via Reddit posts rather than a direct statement.
Confirmed downstream impact across six named brands and two notification waves
Real-world consequence is documented rather than speculative: eight European warehouses stopped shipping, Ceva issued customer notices on 1 August, six named organizations reportedly confirmed impact, and at least three of them (Bol, De Bijenkorf, Valve) went on to notify their own customers. The measure is held below the top band because the number of affected individuals is unquantified and Ceva has not disclosed the operational or data scope itself.
Reporting tracks the record; unquantified scope skews toward understatement
Neither publisher inflates the story: the headline facts — eight warehouses, six notifying brands, no first-party breach at the retailers — are exactly what the sources document, and both explicitly flag that the number of affected people is unknown. The slight negative reflects that the unmeasured variables all point one direction: a rolling 90-day retention window across a 1,700-facility provider with prior extortion claims implies a larger affected population than anything yet stated. Malwarebytes' Scam Guard promotion and its own dark web statistics add promotional framing but do not overstate the incident itself.
Vendor product placement plus self-limiting statements from affected brands
Incentives are visible on both sides of the reporting. Malwarebytes ends its account with repeated pitches for Scam Guard and Malwarebytes Premium Security and supports its threat framing with its own researchers' dark web figures. The affected brands' statements are also incentive-shaped: Bol stresses that 'No Bol systems were affected' and De Bijenkorf enumerates what was not exposed, both narrowing perceived blame while the breached vendor stays silent. SecurityWeek's incentive is ordinary trade-press volume, evidenced by its block of related-breach links.
Two independent outlets agree on the spine; the vendor's own account is missing
Confidence is solid on the timeline, the named affected organizations and the exposed data categories, because two independent publishers converge and much of it rests on first-party company statements. It is limited by the absence of any Ceva statement, the lack of record counts, unresolved attribution and intrusion vector, and reliance on Reddit posts for one publisher's account of Valve's position.
security
One warehouse breach, two brands notifying: CEVA's retention clock set the blast radius1 distinct publisher
security
A North Korean IT worker got hired by a federal agency. Vetting is a security control now.1 distinct publisher
security
Levi Strauss lost corporate files through three laptops and no malware1 distinct publisher
leadership
The greenlight moved: where games leadership capacity is actually accumulating1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 11, 2026
1 article · August 12, 2026