A hack at Ceva Logistics is leaking customer data across banks, retailers, and Steam users

Valve found out on August 7. ING found out around the same time. So did Ajax, Bol, De Bijenkorf, and Ace & Tate. All of them share one thing in common: they trusted a French logistics company called Ceva with their customers’ personal data, and now that data is in someone else’s hands.

According to TechCrunch, the cyberattack on Ceva Logistics began on July 29 and is currently affecting at least eight warehouses across Europe. Ceva confirmed the breach in a statement, describing it as a “cyber intrusion” impacting part of its European contract logistics operations. The company says its security teams activated protocols immediately and that the damage is limited to those eight sites. But for the customers whose names, home addresses, phone numbers, and email addresses were taken, that framing offers little comfort.

Ceva is not a small player. The company pulled in $18.3 billion in revenue in 2025 and operates over a thousand warehouses worldwide. It sits at the center of global supply chains, moving goods from factories to front doors for companies across industries. That scale is exactly what makes it such an attractive target. And it’s also why a breach here doesn’t stay contained to one company or one country.

Dutch retailer Bol confirmed that hackers accessed its warehouse partner’s systems and warned customers their data may have been taken. De Bijenkorf, a luxury department store chain, confirmed order delays and customer data exposure. Football club Ajax, banking group ING, and eyewear brand Ace & Tate all reported that shipping information belonging to their customers was caught in the breach. Valve told Steam hardware buyers directly, via a Reddit post, that Ceva stores their delivery details for 90 days after an order. It’s that kind of quiet, routine data retention that people rarely think about until something like this happens.

The Dutch data protection authority has already received breach reports from ten organizations connected to this incident. That number will likely grow. Shipping and logistics companies have become increasingly attractive targets for cybercriminals, partly because of their physical access to goods in transit, but also because they sit on a goldmine of customer data collected on behalf of dozens or hundreds of other businesses.

What’s frustrating here is the opacity. Ceva’s spokesperson refused to answer basic questions: how much data was taken, whether a ransom demand was received, and what the attackers actually wanted. That silence is a pattern in corporate breach responses, and it does real harm. People can’t protect themselves from phishing attempts or identity fraud if the companies holding their data won’t say what was exposed.

The affected customers span a wide range of industries and countries. That’s the real story. It’s not just a logistics problem. It’s a reminder that every time you hand your address to an online retailer, that data moves through systems you’ve never heard of, held by companies you never agreed to trust.