"A textbook supply chain breach."
Ceva Logistics: scope, timeline, and containment
Ceva Logistics, a subsidiary of the French CMA CGM Group, said a data breach affected its European contract logistics operations — the part of its business that provides warehousing and fulfilment, manufacturing support and aftermarket services. In a brief statement seen by Infosecurity the firm said it notified impacted customers on August 1 and that eight warehouses were affected.
Ceva's statement added: "No other Ceva systems globally were affected, and all other operations continue without incident." An email from Ceva client Valve, republished online, said the cyber-attack ran from July 29 to August 1.
Which customers and locations reported impact
The breach touched a range of European customers. The gaming platform Steam's operator, Valve, sent an email to customers saying Ceva "receives specific delivery-related information from Steam to be able to ship physical hardware to customers in Europe, and told us these are the details the attacker likely took." Other named victims include Dutch online retailer Bol, department store chain De Bijenkorf, football club Ajax and banking firm ING.
Bol warned that restoration of operations at Ceva’s Veerweg location is taking "longer than anticipated" and said this may impact service levels. Valve noted that Ceva retains delivery information for up to 90 days after an order, and that Valve was notifying "all customers we can assume were impacted."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhat data attackers may have obtained
According to messages from affected parties, hackers may have taken names, email and home addresses, phone numbers and order details. Those categories of information are precisely what logistics partners handle when fulfilling shipments and holding short-term order records.
Joseph Perry, cybersecurity researcher and advanced services lead at Arcova, described the sector's appeal to criminals: "They sit at the center of thousands of transactions between businesses and their customers. That makes them an appealing target because a compromise can create operational problems while also giving attackers access to information about the people and products moving through the system." He added that shipping information "is also highly contextual" and can enable convincing phishing and impersonation attempts.
Security experts' immediate warnings and advice
Anna Collard, KnowBe4 CISO advisory, said the incident was a "textbook supply chain breach" and warned of imminent fraud attempts. "I'd expect a wave of 'delivery problem' lures over the coming weeks, messages about a redelivery fee or a request to 'verify' an order," she said. Her practical guidance was specific: "So treat any unexpected message about this order as fake, don't click links or pay fees, and go directly to the retailer's official site by typing the address yourself."
How technologists, affected enterprises, and consumers are responding
- Technologists and security teams: will be monitoring for phishing campaigns that use the stolen delivery data and reassessing how logistics partners are treated within enterprise security boundaries. As Perry put it, these providers must be treated "part of the security and operational environment."
- Affected enterprises and procurement leaders: have begun customer notifications and operational recovery. Ceva reported customer notification on August 1; Valve issued direct notice to potentially impacted customers; Bol has publicly flagged slower recovery at the Veerweg site and possible service impacts.
- End users and consumers: should expect contact from retailers and platforms and heed the specific advice from security practitioners — avoid clicking unexpected links or paying redelivery fees sent in unsolicited messages and verify orders through official channels.
Ceva's breach arrives against a known company history: CMA CGM suffered a ransomware attack in 2020 that temporarily closed its shipping website and applications. For now, Ceva says its other global systems and operations continue without incident. The immediate measures will be operational recovery at the eight affected warehouses and vigilance by customers and security teams for the phishing campaigns experts have forecast.
Original reporting: https://www.infosecurity-magazine.com/news/logistics-ceva-data-breach/




