---
title: "CEVA Logistics Breach: One Shipping Partner, Kn… | Firevault"
description: "A cyberattack on CEVA Logistics disrupted eight European warehouses and exposed customer delivery data held on behalf of retailers including Valve. When a…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/ceva-logistics-breach-europe-knock-on-effects-2026#webpage",
      "url": "https://fire-vault.com/news/ceva-logistics-breach-europe-knock-on-effects-2026",
      "name": "CEVA Logistics Breach: One Shipping Partner, Kn…",
      "description": "A cyberattack on CEVA Logistics disrupted eight European warehouses and exposed customer delivery data held on behalf of retailers including Valve. When a…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/42e30e5a-ca76-4cac-8fd2-9063fe7451a8/ceva-logistics-breach-2026-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/ceva-logistics-breach-europe-knock-on-effects-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/ceva-logistics-breach-europe-knock-on-effects-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "CEVA Logistics Breach: One Shipping Partner, Knock-On Effects Across Europe",
          "item": "https://fire-vault.com/news/ceva-logistics-breach-europe-knock-on-effects-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "CEVA Logistics Breach: One Shipping Partner, Knock-On Effects Across Europe",
      "description": "A cyberattack on CEVA Logistics disrupted eight European warehouses and exposed customer delivery data held on behalf of retailers including Valve. When a supplier holds your customer records, their breach becomes your breach.",
      "url": "https://fire-vault.com/news/ceva-logistics-breach-europe-knock-on-effects-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/42e30e5a-ca76-4cac-8fd2-9063fe7451a8/ceva-logistics-breach-2026-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/42e30e5a-ca76-4cac-8fd2-9063fe7451a8/ceva-logistics-breach-2026-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/42e30e5a-ca76-4cac-8fd2-9063fe7451a8/ceva-logistics-breach-2026-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/42e30e5a-ca76-4cac-8fd2-9063fe7451a8/ceva-logistics-breach-2026-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-08-11T21:00:00+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/ceva-logistics-breach-europe-knock-on-effects-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 507,
      "keywords": "CEVA, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "A cyberattack on CEVA Logistics has spread across Europe through the brands that rely on it. The freight and contract logistics operator, a subsidiary of the CMA CGM Group, told multiple European retailers on 1 August 2026 that an attack had disrupted operations at eight of its European warehouses. Days later, customers of client brands began receiving breach notifications. The wider effects were ",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What happened in the CEVA Logistics breach?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Attackers had access to CEVA Logistics systems between 29 July and 1 August 2026. CEVA told multiple European retailers on 1 August that the attack had disrupted operations at eight of its European warehouses, and customer delivery data handled on behalf of client brands was likely taken."
          }
        },
        {
          "@type": "Question",
          "name": "What data was taken?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "For Steam hardware customers in Europe, Valve stated that names, addresses, telephone numbers, email addresses and the type and price of ordered products were likely compromised. Valve said no payment information, passwords or Steam Guard codes were held by CEVA."
          }
        },
        {
          "@type": "Question",
          "name": "Why did the breach affect so many brands?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "CEVA ships on behalf of many retailers and holds delivery information for up to 90 days after an order. One intrusion at one supplier therefore exposed the customers of multiple unrelated brands across Europe, and each brand carries its own notification duty."
          }
        },
        {
          "@type": "Question",
          "name": "How does Offline Secure Storage reduce this kind of exposure?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Offline Secure Storage keeps the record set that a business genuinely needs to retain, such as customer archives, contracts and gold copy operational data, on dedicated hardware that is physically disconnected when closed. An attacker inside the connected estate cannot read, encrypt or delete what is not connected, so the live system only holds what it needs for the order in front of it."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What HappenedWhy It MattersThe Firevault ViewMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 11 August 2026 

# CEVA Logistics Breach: One Shipping Partner, Knock-On Effects Across Europe

A cyberattack on CEVA Logistics disrupted eight European warehouses and exposed customer delivery data held on behalf of retailers including Valve. When a supplier holds your customer records, their breach becomes your breach.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fceva-logistics-breach-europe-knock-on-effects-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fceva-logistics-breach-europe-knock-on-effects-2026&text=CEVA%20Logistics%20Breach%3A%20One%20Shipping%20Partner%2C%20Knock-On%20Effects%20Across%20Europe%0A%0AA%20cyberattack%20on%20CEVA%20Logistics%20disrupted%20eight%20European%20warehouses%20and%20exposed%20customer%20delivery%20data%20held%20on%20behalf%20of%20retailers%20including%20Valve.%20When%20a%20supplier%20holds%20your%20customer%20records%2C%20their%20breach%20becomes%20your%20breach.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fceva-logistics-breach-europe-knock-on-effects-2026)[](mailto:?subject=CEVA%20Logistics%20Breach%3A%20One%20Shipping%20Partner%2C%20Knock-On%20Effects%20Across%20Europe&body=A%20cyberattack%20on%20CEVA%20Logistics%20disrupted%20eight%20European%20warehouses%20and%20exposed%20customer%20delivery%20data%20held%20on%20behalf%20of%20retailers%20including%20Valve.%20When%20a%20supplier%20holds%20your%20customer%20records%2C%20their%20breach%20becomes%20your%20breach.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fceva-logistics-breach-europe-knock-on-effects-2026)

![Darkened European logistics warehouse at night with halted parcel conveyors, stacked pallets and an unpowered scanning terminal](/__l5e/assets-v1/42e30e5a-ca76-4cac-8fd2-9063fe7451a8/ceva-logistics-breach-2026-2x.jpg)

Darkened European logistics warehouse at night with halted parcel conveyors, stacked pallets and an unpowered scanning terminal

Why it matters

## What this means for organisations holding critical data

A cyberattack on CEVA Logistics disrupted eight European warehouses and exposed customer delivery data held on behalf of retailers including Valve. When a supplier holds your customer records, their breach becomes your breach.

In this analysis

1.  01 [What Happened](#section-0)
2.  02 [Why It Matters](#section-1)

**On this page**[What Happened](#section-0)[Why It Matters](#section-1)

**A cyberattack on CEVA Logistics has spread across Europe through the brands that rely on it.** The freight and contract logistics operator, a subsidiary of the CMA CGM Group, told multiple European retailers on 1 August 2026 that an attack had disrupted operations at eight of its European warehouses. Days later, customers of client brands began receiving breach notifications. The wider effects were [reported by TechRadar Pro](https://www.techradar.com/pro/security/the-ceva-logistics-data-breach-is-having-major-knock-on-effects-across-europe-heres-what-we-know), and the Valve notification was [reported by BleepingComputer](https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/) on 10 August 2026.

## What Happened

According to notifications sent to customers, attackers had access to CEVA Logistics servers between 29 July and 1 August 2026. Valve, which uses CEVA to ship Steam hardware to customers in Europe, told affected buyers that names, addresses, telephone numbers, email addresses and the type and price of ordered products were likely taken. Valve stated that CEVA does not hold payment information, passwords or Steam Guard codes.

The scale of the notification was set by data retention rather than by the attack itself. CEVA retains delivery information for up to 90 days after an order, so Valve wrote to every customer it had to assume was affected. Dutch retailers including bol and de Bijenkorf warned their own customers in the same period, and reporting confirmed operational disruption at eight European warehouses.

## Why It Matters

CEVA operates around 1,000 warehouses, handled 15 million shipments last year and reported 18.3 billion dollars in revenues in 2025. That reach is the point. None of the affected retailers were breached. One supplier was, and the consequence landed on every brand whose customer data sat inside that supplier estate, along with the notification duty, the regulator contact and the phishing wave that follows.

Valve warned customers that criminals may quote a real delivery address back to them to appear genuine, then ask them to confirm a delivery, pay a small customs or redelivery fee, or sign in to verify an order. Accurate logistics data makes fraud convincing in a way that a stolen password never does.

## The Firevault View

Two design failures are visible here, and neither is exotic. The first is connectivity: a live operational system held a rolling archive of customer records reachable from the network. The second is retention: data was kept online long after the business purpose ended, so the breach window covered 90 days of orders rather than the shipments in flight.

[Offline Secure Storage](/offline-secure-storage)® addresses both. Records that must be retained for audit, warranty, dispute or contractual reasons are held on dedicated hardware that is physically disconnected when it is not in use, and the connected system keeps only what it needs to complete the work in front of it. An attacker inside the online estate cannot read, encrypt or delete a copy that is not connected, and recovery of operational data starts from a verified gold copy rather than from a negotiation.

For any organisation that ships, stores or processes on behalf of clients, the question a customer will now ask is simple. Where does our data physically sit when nobody is using it?

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Trezor breach reaches 81,000 customers because a supplier never deleted the data](/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg)

Breach Analysis 

### Trezor breach reaches 81,000 customers because a supplier never deleted the data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

8 Sept 2026 3 min 







](/news/trezor-shipmonk-data-breach-81000-customers-2026)[

![Quinn Emanuel and McDermott breached as law firms become the soft route to client data](/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg)

Breach Analysis 

### Quinn Emanuel and McDermott breached as law firms become the soft route to client data

Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One compromised user account was enough.

8 Sept 2026 4 min 







](/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026)[

![Mathspace breach exposes more than one million students, staff and parents](/images/news/mathspace-data-breach-one-million-students-2026.jpg)

Breach Analysis 

### Mathspace breach exposes more than one million students, staff and parents

An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across Australia and New Zealand.

8 Sept 2026 4 min 







](/news/mathspace-data-breach-one-million-students-2026)[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)[

![Adobe Commerce attacked immediately after session breach vulnerability](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png)

Breach Analysis 

### Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

14 Aug 2026 4 min 







](/news/adobe-commerce-session-vulnerability-exploited-after-disclosure)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)