Breaking
Parliament session extended to clear the backlog of budget billsDhaka–Chattogram expressway section opens to traffic ahead of Eid rushNational team names squad for the home Test seriesCentral bank holds policy rate, flags inflation watch for Q4Flood forecast: water levels expected to recede in northern districts by weekendParliament session extended to clear the backlog of budget billsDhaka–Chattogram expressway section opens to traffic ahead of Eid rushNational team names squad for the home Test seriesCentral bank holds policy rate, flags inflation watch for Q4Flood forecast: water levels expected to recede in northern districts by weekend
Technology

Cyberattack Hits Shipping Giant Ceva Logistics: Customer Data Compromised Across Major Brands

1 day ago

Published in Enterprise & Cybersecurity

Key Takeaways:

  • The Incident: France-headquartered shipping giant Ceva Logistics suffered a major cyberattack impacting at least eight European warehouses.

  • The Impact: Hackers infiltrated systems containing personal shipping data, including names, delivery addresses, phone numbers, and email addresses.

  • Affected Brands: High-profile clients including Valve, Dutch e-commerce giant Bol, luxury retailer De Bijenkorf, banking giant ING, Ajax football club, and Ace & Tate.

  • Current Status: Ceva has restored some affected applications and is investigating alongside European regulatory authorities.

A Major Blow to the Global Supply Chain

PARIS / AMSTERDAM — Ceva Logistics, one of the world’s largest third-party shipping and supply chain providers, has been hit by a coordinated cyberattack. The breach has disrupted operations across Europe and compromised sensitive customer information belonging to several major global retailers.

Ceva, which generated $18.3 billion in revenue in 2025 and operates more than 1,000 facilities worldwide, confirmed that the operational fallout is currently restricted to eight contract logistics warehouses in Europe. According to freight industry reports, the intrusion began on July 29, leading to widespread shipping backlogs, canceled orders, and severe delivery delays.

Retailers Alert Customers Over Stolen Personal Data

While logistics delays pose a logistical headache, the security footprint of the breach is equally alarming. Because Ceva fulfills direct-to-door deliveries for retail partners, its systems hold extensive personal customer data. Hackers managed to exfiltrate database information containing:

  • Full Names

  • Home Addresses

  • Phone Numbers

  • Email Addresses

Who Has Been Impacted So Far?

Affected BrandIndustryStated ImpactValveGaming / HardwareSent data breach notices to recent Steam hardware buyers; confirmed Ceva retains shipping data for 90 days.BolE-CommerceWarned customers of potential data exposure, order delays, and possible order cancellations.De BijenkorfLuxury RetailConfirmed delivery delays following the breach of customer delivery records.INGFinancial ServicesCustomer shipping information exposed via impacted Ceva routes.Ajax FCSports & RetailFan shop delivery data compromised.Ace & TateEyewearCustomer logistics data exposed.

In a notice shared with affected users on Reddit, gaming titan Valve confirmed it was notified of the incident on August 7, warning customers who recently ordered Steam hardware that their delivery information had been intercepted.

The Target on the Back of Global Logistics

Cybersecurity experts point out that shipping and logistics conglomerates have become primary targets for cybercriminals in recent years. By compromising enterprise shipping networks, threat actors gain the ability to hijack cargo routes, manipulate freight data, or extract massive volumes of consumer address records for secondary phishing campaigns.

Ceva Responds, Regulators Launch Investigation

Ceva spokesperson Ryan Fisher confirmed the ongoing intrusion but declined to comment on whether ransomware was involved or if the hackers had issued an extortion demand.

In an official statement, Ceva noted:

"On Aug. 1, CEVA Logistics confirmed to affected customers that a cyber intrusion was impacting part of its European contract logistics operations. As soon as the incident was identified, CEVA’s cybersecurity teams immediately activated its security protocols and launched a thorough investigation, which is still ongoing."

"The operational impact is limited to eight warehouses. No other CEVA systems globally were affected, and all other operations continue without incident."

Ceva's main web portal experienced loading failures on Monday as recovery efforts continued, though the firm stated several key operational applications have been brought back online.

The breach has triggered regulatory intervention. Mark Schenkel, spokesperson for the Dutch Data Protection Authority, confirmed that the watchdog has already received formal data breach notifications from at least 10 organizations tied to the Ceva breach.

Cyberattack Hits Shipping Giant Ceva Logistics: Customer Data Compromised Across Major Brands — Digital Connect News · Digital Connect News