The attackers never touched Steam, ING, or bol. They landed inside the one company all three quietly rely on to move parcels: Ceva Logistics. That is why a single break-in at a shipping firm is showing up at the same moment as a data-loss notice from a bank, a luxury department store, a football club, and everyone who bought Steam hardware in Europe.
The pattern is the story. When unrelated brands lean on the same logistics or fulfillment provider, they quietly inherit its blast radius too. One intrusion, a dozen separate disclosures, spread across industries that otherwise share nothing.
What happened
According to Ceva's customer notice and reporting by TechCrunch, the intrusion ran from July 29 to August 1, 2026, striking Ceva Logistics directly. On that final day the company told affected customers that the attack was knocking out part of its European contract-logistics operation. Reporting from FreightWaves puts the damage at eight of Ceva's European warehouses, a sliver of the 1,000-plus sites it runs worldwide. Dutch retailer bol says the intruders reached two order-processing systems inside one distribution center.
The roster of downstream brands now writing to customers keeps widening: bol, luxury retailer De Bijenkorf, eyewear maker Ace & Tate, banking group ING, football club Ajax, and Valve, which leans on Ceva to deliver Steam hardware across Europe. Valve's notice explains why so many buyers were caught: Ceva hangs on to each order's delivery details for as long as 90 days, so anyone who bought in that window landed in the exposed set.
What was exposed, and what was not
The stolen fields line up across every disclosure: the buyer's name, their home and email addresses, a phone number, and a record of what they ordered and where it was headed. Business customers lost VAT numbers on top of that. The exclusions carry just as much weight. Valve, bol and De Bijenkorf each say the same thing, that card numbers, account passwords, and Steam's second-factor Guard codes were never handed to Ceva in the first place, so none of that sat on the systems the attackers reached.
- Exposed: buyer names, home and email addresses, phone numbers, order and delivery details, and some business VAT numbers.
- Safe: account passwords, payment cards, and Steam Guard codes, none of which the shipping partner ever held.
Nobody named yet
As of August 10, 2026, no group or ransomware crew has been publicly tied to the attack, and Ceva has not said whether anyone demanded money. The Dutch Data Protection Authority and other agencies are digging in. We are pinning this on no one, and neither should anyone else until a primary source does.
Why "no passwords taken" is not the reassurance it sounds like
Here is the trap. The honest, accurate message every affected brand is sending is that your login is safe and there is nothing to reset. True. It is also the precise moment a customer eases off, and it arrives just ahead of a phishing run that can name their real address and cite a genuine recent order. Contact details married to an order history make a ready-made kit for convincing lures and for business email compromise, the scam where an attacker poses as a trusted sender to reroute a payment or steal a login. The comfort and the danger point in opposite directions, and the crews running the lures understand that better than the victims do.
There is a second, quieter lesson for any business built on outsourced fulfillment: your window of exposure was set by a partner's retention policy you likely never read. Steam buyers were swept in because their delivery data sat at Ceva for three months. You absorb a vendor's retention habits, logging, and security posture whether or not you ever audited them.
What to do this week
If you run anything customer-facing, treat this as a rehearsal for the third-party breach you will one day receive rather than cause:
- Map who holds your customers' data. Write down every logistics, fulfillment, payment, and marketing vendor that stores customer contact or order data, and how long each keeps it. Trim that retention wherever a partner will let you.
- Get in front of the phishing. Expect targeted lures built around real orders. Brief your support and finance staff, and tell customers plainly, the way Valve did: treat any surprise message as fake, and there is no password to change.
- Watch your own front door. Leaked contact data fuels credential-stuffing and account-takeover runs against your own portals. Rate-limit logins, alert on bursts of failed sign-ins, and flag any login that does not match a customer's normal pattern.
- Fix the contract, not just the incident. Bake breach-notification deadlines, data minimization, and retention limits into vendor agreements before the next partner is the one that gets hit.
For the machines and accounts you actually control, the counter to the follow-on is plain visibility. Suriq watches your hosts and their logs for exactly the probing a leak like this sets off, the odd login, the sudden run of authentication failures, so a supplier's bad week does not quietly turn into yours. The break-in happened in someone else's warehouse. The phishing and account-takeover attempts will show up at your door.