Breach Analysis·11 August 2026

CEVA Logistics Breach: One Shipping Partner, Knock-On Effects Across Europe

A cyberattack on CEVA Logistics disrupted eight European warehouses and exposed customer delivery data held on behalf of retailers including Valve. When a supplier holds your customer records, their breach becomes your breach.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
3 min read
Share
Darkened European logistics warehouse at night with halted parcel conveyors, stacked pallets and an unpowered scanning terminal
Breach Analysis

Article record

Breach AnalysisCategory
11 August 2026Published
3 min readReading time
Mark FermorWritten by
Darkened European logistics warehouse at night with halted parcel conveyors, stacked pallets and an unpowered scanning terminal

Why it matters

What this means for organisations holding critical data

A cyberattack on CEVA Logistics disrupted eight European warehouses and exposed customer delivery data held on behalf of retailers including Valve. When a supplier holds your customer records, their breach becomes your breach.

A cyberattack on CEVA Logistics has spread across Europe through the brands that rely on it. The freight and contract logistics operator, a subsidiary of the CMA CGM Group, told multiple European retailers on 1 August 2026 that an attack had disrupted operations at eight of its European warehouses. Days later, customers of client brands began receiving breach notifications. The wider effects were reported by TechRadar Pro, and the Valve notification was reported by BleepingComputer on 10 August 2026.

What Happened

According to notifications sent to customers, attackers had access to CEVA Logistics servers between 29 July and 1 August 2026. Valve, which uses CEVA to ship Steam hardware to customers in Europe, told affected buyers that names, addresses, telephone numbers, email addresses and the type and price of ordered products were likely taken. Valve stated that CEVA does not hold payment information, passwords or Steam Guard codes.

The scale of the notification was set by data retention rather than by the attack itself. CEVA retains delivery information for up to 90 days after an order, so Valve wrote to every customer it had to assume was affected. Dutch retailers including bol and de Bijenkorf warned their own customers in the same period, and reporting confirmed operational disruption at eight European warehouses.

Why It Matters

CEVA operates around 1,000 warehouses, handled 15 million shipments last year and reported 18.3 billion dollars in revenues in 2025. That reach is the point. None of the affected retailers were breached. One supplier was, and the consequence landed on every brand whose customer data sat inside that supplier estate, along with the notification duty, the regulator contact and the phishing wave that follows.

Valve warned customers that criminals may quote a real delivery address back to them to appear genuine, then ask them to confirm a delivery, pay a small customs or redelivery fee, or sign in to verify an order. Accurate logistics data makes fraud convincing in a way that a stolen password never does.

The Firevault View

Two design failures are visible here, and neither is exotic. The first is connectivity: a live operational system held a rolling archive of customer records reachable from the network. The second is retention: data was kept online long after the business purpose ended, so the breach window covered 90 days of orders rather than the shipments in flight.

Offline Secure Storage® addresses both. Records that must be retained for audit, warranty, dispute or contractual reasons are held on dedicated hardware that is physically disconnected when it is not in use, and the connected system keeps only what it needs to complete the work in front of it. An attacker inside the online estate cannot read, encrypt or delete a copy that is not connected, and recovery of operational data starts from a verified gold copy rather than from a negotiation.

For any organisation that ships, stores or processes on behalf of clients, the question a customer will now ask is simple. Where does our data physically sit when nobody is using it?

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Breach Analysis11 August 20263 min read

CEVA Logistics Breach: One Shipping Partner, Knock-On Effects Across Europe

A cyberattack on CEVA Logistics disrupted eight European warehouses and exposed customer delivery data held on behalf of retailers including Valve. When a supplier holds your customer records, their breach becomes your breach.

CEVA Logistics Breach: One Shipping Partner, Knock-On Effects Across Europe
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy