A cyberattack on Ceva Logistics, one of the world’s largest shipping and logistics companies, has triggered a data breach affecting a surprisingly wide range of businesses and their customers, from Dutch banks and retailers to video game giant Valve. If you’ve recently ordered something online and had it shipped through a partner using Ceva’s warehousing network, your personal information may have been exposed.
What Happened at Ceva Logistics
Ceva Logistics is a France-headquartered shipping and logistics giant that brought in $18.3 billion in revenue in 2025 and operates over a thousand warehouses worldwide. According to industry news site FreightWaves, the cyberattack began on July 29, 2026, and is causing shipping delays for goods stored in the affected facilities.
In a statement to TechCrunch, Ceva confirmed the intrusion: “On Aug. 1, CEVA Logistics confirmed to affected customers that a cyber intrusion was impacting part of its European contract logistics operations… The operational impact is limited to eight warehouses. No other CEVA systems globally were affected, and all other operations continue without incident.”
Ceva has not disclosed how much personal data was taken or whether it has received any ransom demand from the attackers, and a company spokesperson declined to answer those specific questions when asked by TechCrunch.
Who’s Been Affected So Far
Because Ceva handles warehousing and last-mile shipping logistics for a wide range of companies, the breach has rippled outward to affect customers who may have never heard of Ceva Logistics at all:
- Bol, a major Dutch online retail giant, warned customers their data may have been taken through its warehousing partnership with Ceva, and said it expects order delays and cancellations as a result.
- De Bijenkorf, a Dutch luxury retailer, similarly confirmed order delays following the theft of customer data.
- Football club Ajax, banking giant ING, and eyeglass maker Ace & Tate all reported that their customers’ shipping information was affected.
- Valve, the video game giant behind Steam, told customers who recently purchased Steam hardware that their personal information was taken in the incident. Valve noted that Ceva stores shipping and delivery information for 90 days following an order.
The data reportedly taken includes names, home addresses, phone numbers, and email addresses used to place orders through Ceva’s affected systems, standard information used for delivery, but sensitive enough to enable follow-on phishing, scam attempts, or identity-related fraud if it falls into the wrong hands.
Why Logistics Companies Are Becoming Prime Targets
This isn’t an isolated incident. Shipping and logistics companies have become an increasingly attractive target for cybercriminals in recent years, and for reasons that go beyond simple data theft. Attackers have shown growing interest in compromising logistics systems specifically for their ability to access and hijack trucks and shipping containers, redirecting real-world goods into the hands of criminal networks, a threat distinct from the more familiar pattern of stealing customer data for resale.
That combination, valuable customer data plus potential access to physical supply chains, makes logistics providers a uniquely high-value target compared to a typical retailer or software company.
What’s Being Done About It
Ceva says some of its affected applications and services are back online, and that it’s working with law enforcement authorities. Dutch data protection officials confirmed they’ve received data breach reports from 10 organizations in connection with the incident, and an investigation is underway in the Netherlands. As of the time of reporting, Ceva’s own website was intermittently failing to load properly, suggesting the operational impact was still being resolved days after the initial intrusion.
What Affected Customers Should Do
If you’ve received a notification from a retailer, bank, or other company that your shipping data may have been exposed through the Ceva breach, a few practical steps are worth taking:
- Watch for phishing attempts referencing recent orders or deliveries, since attackers with your name, address, and order history can craft highly convincing scam messages.
- Be cautious of unexpected delivery-related texts or emails, especially ones asking you to click a link to “confirm” a shipment or address, a common tactic following logistics data breaches.
- Check with the specific retailer you ordered from to confirm whether your data was among the information taken, since exposure varies by which company’s shipments passed through the affected warehouses.
- Consider a credit freeze or fraud alert if you’re concerned about identity theft, particularly if the breach notification indicates more sensitive information was involved.
The Bigger Picture
The Ceva Logistics breach is a clear reminder that in modern e-commerce, your data security depends not just on the retailer you’re buying from, but on an entire invisible chain of shipping, warehousing, and logistics partners you never directly interact with or choose. A single breach at one shipping and logistics company was enough to expose customers of a major bank, a soccer club, an eyewear brand, and a video game hardware maker, all at once, illustrating just how interconnected, and how fragile, modern supply chain data security has become.
For continuing coverage of data breaches and the latest cybersecurity news affecting consumers and businesses, keep following Tech News Reports for ongoing updates.

