A major cyberattack on shipping giant CEVA Logistics has exposed the personal shipping information of European retail customers. Several high profile clients, including video game publisher Valve and Dutch retail giant Bol, confirmed that hackers infiltrated CEVA databases to steal delivery details. The shipping company has isolated its systems while investigators evaluate the full extent of the data breach.
The intrusion disrupted operations at 8 European warehouses, causing logistics delays and order cancellations across the continent. CEVA operates over 1000 warehouses globally and reported $18.3 billion in revenue last year, making it a major target for cybercriminals. Hackers managed to access delivery databases, taking customer names, physical addresses, phone numbers, and email details used for shipments.
Valve began notifying European customers who recently purchased Steam hardware that their details were likely compromised in the incident. Because CEVA stores shipping records for up to 90 days after an order, anyone who bought hardware recently is vulnerable. The gaming giant clarified that core accounts remain secure. The compromised shipping databases do not contain payment info, passwords, or Steam Guard codes.
Other major retail brands have reported similar leaks of customer data. Dutch luxury retailer De Bijenkorf, banking firm ING, sports club Ajax, and eyewear brand Ace and Tate all confirmed their distribution networks were hit. Valve warned customers to watch out for targeted phishing scams through emails or text messages. Bad actors might quote stolen shipping addresses to demand fake delivery or customs fees.
CEVA confirmed the security incident and stated that its cybersecurity teams activated defensive protocols immediately upon discovering the breach. Operational damage is reportedly limited to the European contract logistics branch. The shipping firm is currently working with external investigators and local data protection authorities to determine how the intrusion occurred.
