CEVA Logistics Breach: One Shipping Partner, Knock-On Effects Across Europe
A cyberattack on CEVA Logistics disrupted eight European warehouses and exposed customer delivery data held on behalf of retailers including Valve. When a supplier holds your customer records, their breach becomes your breach.
Article record
Why it matters
What this means for organisations holding critical data
A cyberattack on CEVA Logistics disrupted eight European warehouses and exposed customer delivery data held on behalf of retailers including Valve. When a supplier holds your customer records, their breach becomes your breach.
A cyberattack on CEVA Logistics has spread across Europe through the brands that rely on it. The freight and contract logistics operator, a subsidiary of the CMA CGM Group, told multiple European retailers on 1 August 2026 that an attack had disrupted operations at eight of its European warehouses. Days later, customers of client brands began receiving breach notifications. The wider effects were reported by TechRadar Pro, and the Valve notification was reported by BleepingComputer on 10 August 2026.
What Happened
According to notifications sent to customers, attackers had access to CEVA Logistics servers between 29 July and 1 August 2026. Valve, which uses CEVA to ship Steam hardware to customers in Europe, told affected buyers that names, addresses, telephone numbers, email addresses and the type and price of ordered products were likely taken. Valve stated that CEVA does not hold payment information, passwords or Steam Guard codes.
The scale of the notification was set by data retention rather than by the attack itself. CEVA retains delivery information for up to 90 days after an order, so Valve wrote to every customer it had to assume was affected. Dutch retailers including bol and de Bijenkorf warned their own customers in the same period, and reporting confirmed operational disruption at eight European warehouses.
Why It Matters
CEVA operates around 1,000 warehouses, handled 15 million shipments last year and reported 18.3 billion dollars in revenues in 2025. That reach is the point. None of the affected retailers were breached. One supplier was, and the consequence landed on every brand whose customer data sat inside that supplier estate, along with the notification duty, the regulator contact and the phishing wave that follows.
Valve warned customers that criminals may quote a real delivery address back to them to appear genuine, then ask them to confirm a delivery, pay a small customs or redelivery fee, or sign in to verify an order. Accurate logistics data makes fraud convincing in a way that a stolen password never does.
The Firevault View
Two design failures are visible here, and neither is exotic. The first is connectivity: a live operational system held a rolling archive of customer records reachable from the network. The second is retention: data was kept online long after the business purpose ended, so the breach window covered 90 days of orders rather than the shipments in flight.
Offline Secure Storage® addresses both. Records that must be retained for audit, warranty, dispute or contractual reasons are held on dedicated hardware that is physically disconnected when it is not in use, and the connected system keeps only what it needs to complete the work in front of it. An attacker inside the online estate cannot read, encrypt or delete a copy that is not connected, and recovery of operational data starts from a verified gold copy rather than from a negotiation.
For any organisation that ships, stores or processes on behalf of clients, the question a customer will now ask is simple. Where does our data physically sit when nobody is using it?
How Firevault would handle this
Physical disconnection removes the path an attacker needs
Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.






