Skip to content

Security2 publishers3 min readPublished Updated

Eight warehouses down, six brands notifying: the Ceva outage nobody's plan modelled

A logistics contractor's intrusion stopped shipments and exposed customer delivery data at Bol, De Bijenkorf, ING and Valve. None of them were breached themselves.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Eight warehouses down, six brands notifying: the Ceva outage nobody's plan modelled
Photo: freightwaves.com

What happened

  • Ceva Logistics is a subsidiary of CMA CGM Group, headquartered in France, providing contract logistics and air, ocean, ground and finished vehicle transport services.
  • Ceva Logistics' European operations were disrupted after hackers compromised its systems; eight warehouses across Europe were affected.
  • The disruption occurred on 29 July and the company was still working to restore impacted services.
  • On 1 August, Ceva notified affected customers of the cyberattack, informing them that goods stored in the disrupted warehouses were not shipping.
  • Multiple organizations reportedly confirmed impact from the incident, including Dutch retailers Bol and De Bijenkorf, ING, Ace & Tate, Amsterdam football club Ajax, and video game provider Valve.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Ceva Logistics, the French-headquartered contract logistics arm of CMA CGM Group, had eight European warehouses disrupted by an intrusion that began on 29 July, and on 1 August told affected customers that goods held in those sites were not shipping [1][2][3][4]. Impact was then confirmed by Dutch retailers Bol and De Bijenkorf, ING, Ace & Tate, football club Ajax and Valve [5] - none of whose own systems were compromised, which is the whole problem.

The pattern in each downstream disclosure is the same. Bol said the incident involved two systems used to process orders from one of its fulfilment centres, that no Bol systems were affected, and that data of customers whose orders went through that location may have been viewed or copied [6]. De Bijenkorf said the exposure may cover names, addresses, email addresses, phone numbers and online order details, plus entity names and identification numbers for business customers, and explicitly excluded payment details, IBANs, card data, usernames and passwords [7][8]. Valve warned on 10 August that names, home addresses, phone numbers, Steam account email addresses and hardware order details were exposed, with passwords and payment information untouched [9].

The timeline is where the third-party dependency shows its teeth. Malwarebytes puts the attack window at 29 July to 1 August 2026, says Valve learned of it on 7 August and began notifying customers three days later [10][11] - nine days from intrusion to awareness and twelve to customer notice [1]. Bol and De Bijenkorf were reportedly told on 1 August [12], six days before Valve knew anything [2]. One incident, one supplier, and a notification clock that started on a different date for each brand attached to it.

Retention policy sets the blast radius, and the brands did not set it. Ceva holds delivery data for roughly 90 days after shipment, so anyone in Europe who received a Steam Deck, Steam Controller or Steam Machine in the preceding three months could be affected [13]. Valve confirmed the three-month retention when telling customers their delivery information was likely compromised [14]. Neither Valve nor Ceva has said how many records were involved [15], and it remains unclear how the attackers got in or who they were [16].

The consequence is fraud with real details in it. Malwarebytes notes that a scammer holding a genuine order and delivery address can ask by email, text or phone for a small customs or redelivery fee, or for a sign-in to verify an order [17]. Valve's advice to customers is to treat any message referencing a recent Steam hardware order as fake, including ones that quote the address correctly, and it points out that Steam Support never contacts users by email, Steam Chat or Discord [18][19]. For scale on the market these records feed, Malwarebytes says its researchers found more than 7,500 compromised datasets containing over 8.4 billion records on the dark web in the first half of 2026 [20].

This is not Ceva's first incident either: the extortion group Coinbase Cartel claimed two attacks on the company last year [21].

What to watch: whether Ceva publishes an initial access account and a record count, since six notifying brands currently have none; whether the affected-customer list grows beyond the Netherlands, given Ceva runs more than 1,700 facilities across 170 countries [22]; and whether any of the notifying organisations discloses that it knew, before 29 July, how long its fulfilment partner retained shipping data. That last one is the test of whether these plans modelled the dependency or discovered it.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories