Decoding the world of cybersecurity

CEVA attack spreads through European supply chains

A cyberattack affecting eight CEVA Logistics warehouses has disrupted European fulfilment and exposed customer information held on behalf of retailers, a bank, a football club, and Valve.

CEVA attack spreads through European supply chains
Summary
  • CEVA says the operational impact is limited to eight warehouses within its European contract logistics business.
  • Customer organisations have disclosed potential exposure of names, addresses, contact details, and order information held for fulfilment purposes.
  • Delivery delays and suspended data transfers show how a logistics-provider compromise can become both a data and operational incident for downstream customers.

A cyberattack at CEVA Logistics is producing data and operational consequences across several European customers, including retailers, ING, Ajax, and Valve, illustrating how one logistics provider can concentrate both personal information and customer-facing business processes.

CEVA told affected customers on 1 August that a cyber intrusion was affecting part of its European contract logistics operation. In a statement subsequently provided to TechCrunch, the company said the operational impact was limited to eight warehouses and that its investigation remained ongoing.

Retailers bol and De Bijenkorf were among the first organisations to disclose consequences from the incident. Ajax, ING, Ace & Tate, and Valve have since warned customers about data or operational exposure linked to fulfilment systems used by CEVA.

The information differs between customers but includes combinations of names, postal addresses, email addresses, telephone numbers, order information, and other delivery-related records. Organisations have separately emphasised that more sensitive categories, such as payment credentials, bank-account information, passwords, or account authentication data, were not stored in the affected logistics systems in their cases.

Valve told European customers who ordered Steam hardware that personal and order information held by its shipping partner was likely compromised. The company said CEVA did not have access to Steam passwords, payment information, or Steam Guard authentication codes.

ING’s exposure concerns customers who ordered physical products through a loyalty programme rather than compromise of the bank’s core systems. Ace & Tate has similarly said financial information, usernames, passwords, and spectacle prescriptions were outside the affected data set.

The incident is also affecting operations. Some organisations suspended data exchanges with the logistics provider after being notified, while customers have faced delays involving orders, returns, refunds, or deliveries. Bol said disruption at the warehouse partner affected part of its logistics operation.

That combination makes the attack more than a conventional third-party data breach. A logistics provider may simultaneously hold customer records, operate fulfilment systems, manage inventory flows, and perform the physical activity needed to complete a sale. Interrupting the provider can therefore reach downstream customers without attackers compromising their corporate networks directly.

The exposed information also carries residual fraud risk even where payment data remains protected. Genuine combinations of names, delivery addresses, order information, and recent purchases can make later phishing or delivery impersonation more credible because an attacker can reproduce details the recipient expects a legitimate company to know.

European data-protection obligations add another layer to that dependency. Individual CEVA customers must assess the data processed on their behalf, determine which people are affected, and make their own regulatory or customer notifications where required, even though the original technical compromise sits inside a supplier.

The affected organisations have therefore had to treat the same upstream cyberattack as different internal events: a customer-notification problem, a fulfilment disruption, a privacy incident, or a supplier-assurance issue depending on how they use CEVA.

CEVA has not publicly attributed the intrusion to a named threat actor, and the full volume of affected records remains unclear. The expanding customer disclosures nevertheless demonstrate the systemic characteristic of outsourced logistics — one compromised provider can create parallel incidents across organisations whose own networks remain untouched.

×