Home/ Blog/ Security news/ Article
Blog · Security news

A breach at shipping partner Ceva Logistics exposed customer data for Steam, ING and other brands

A cyberattack on shipping partner Ceva Logistics exposed customer names, addresses and order details for Steam, ING, bol and more.

Shipping hub conveyor belts converge as delivery labels drift, evoking the Ceva Logistics data breach

The attackers never touched Steam, ING, or bol. They landed inside the one company all three quietly rely on to move parcels: Ceva Logistics. That is why a single break-in at a shipping firm is showing up at the same moment as a data-loss notice from a bank, a luxury department store, a football club, and everyone who bought Steam hardware in Europe.

The pattern is the story. When unrelated brands lean on the same logistics or fulfillment provider, they quietly inherit its blast radius too. One intrusion, a dozen separate disclosures, spread across industries that otherwise share nothing.

What happened

According to Ceva's customer notice and reporting by TechCrunch, the intrusion ran from July 29 to August 1, 2026, striking Ceva Logistics directly. On that final day the company told affected customers that the attack was knocking out part of its European contract-logistics operation. Reporting from FreightWaves puts the damage at eight of Ceva's European warehouses, a sliver of the 1,000-plus sites it runs worldwide. Dutch retailer bol says the intruders reached two order-processing systems inside one distribution center.

The roster of downstream brands now writing to customers keeps widening: bol, luxury retailer De Bijenkorf, eyewear maker Ace & Tate, banking group ING, football club Ajax, and Valve, which leans on Ceva to deliver Steam hardware across Europe. Valve's notice explains why so many buyers were caught: Ceva hangs on to each order's delivery details for as long as 90 days, so anyone who bought in that window landed in the exposed set.

What was exposed, and what was not

The stolen fields line up across every disclosure: the buyer's name, their home and email addresses, a phone number, and a record of what they ordered and where it was headed. Business customers lost VAT numbers on top of that. The exclusions carry just as much weight. Valve, bol and De Bijenkorf each say the same thing, that card numbers, account passwords, and Steam's second-factor Guard codes were never handed to Ceva in the first place, so none of that sat on the systems the attackers reached.

  • Exposed: buyer names, home and email addresses, phone numbers, order and delivery details, and some business VAT numbers.
  • Safe: account passwords, payment cards, and Steam Guard codes, none of which the shipping partner ever held.

Nobody named yet

As of August 10, 2026, no group or ransomware crew has been publicly tied to the attack, and Ceva has not said whether anyone demanded money. The Dutch Data Protection Authority and other agencies are digging in. We are pinning this on no one, and neither should anyone else until a primary source does.

Why "no passwords taken" is not the reassurance it sounds like

Here is the trap. The honest, accurate message every affected brand is sending is that your login is safe and there is nothing to reset. True. It is also the precise moment a customer eases off, and it arrives just ahead of a phishing run that can name their real address and cite a genuine recent order. Contact details married to an order history make a ready-made kit for convincing lures and for business email compromise, the scam where an attacker poses as a trusted sender to reroute a payment or steal a login. The comfort and the danger point in opposite directions, and the crews running the lures understand that better than the victims do.

There is a second, quieter lesson for any business built on outsourced fulfillment: your window of exposure was set by a partner's retention policy you likely never read. Steam buyers were swept in because their delivery data sat at Ceva for three months. You absorb a vendor's retention habits, logging, and security posture whether or not you ever audited them.

What to do this week

If you run anything customer-facing, treat this as a rehearsal for the third-party breach you will one day receive rather than cause:

  • Map who holds your customers' data. Write down every logistics, fulfillment, payment, and marketing vendor that stores customer contact or order data, and how long each keeps it. Trim that retention wherever a partner will let you.
  • Get in front of the phishing. Expect targeted lures built around real orders. Brief your support and finance staff, and tell customers plainly, the way Valve did: treat any surprise message as fake, and there is no password to change.
  • Watch your own front door. Leaked contact data fuels credential-stuffing and account-takeover runs against your own portals. Rate-limit logins, alert on bursts of failed sign-ins, and flag any login that does not match a customer's normal pattern.
  • Fix the contract, not just the incident. Bake breach-notification deadlines, data minimization, and retention limits into vendor agreements before the next partner is the one that gets hit.

For the machines and accounts you actually control, the counter to the follow-on is plain visibility. Suriq watches your hosts and their logs for exactly the probing a leak like this sets off, the odd login, the sudden run of authentication failures, so a supplier's bad week does not quietly turn into yours. The break-in happened in someone else's warehouse. The phishing and account-takeover attempts will show up at your door.

Topics

Frequently asked questions

Was Steam or Valve itself hacked in the Ceva Logistics breach?

No. Valve's own systems were not breached. The exposed data was held at Ceva Logistics, the partner that ships Steam hardware to customers in Europe. Valve says passwords, payment details and Steam Guard codes were never on Ceva's systems.

What customer data was exposed in the Ceva Logistics breach?

Names, home and email addresses, phone numbers, and order or shipping details, plus some business VAT numbers. Account passwords and payment-card data were not stored on Ceva's systems, according to bol, De Bijenkorf and Valve.

Do affected customers need to change their password?

No. Passwords were not exposed, so a reset is not required. The bigger risk is phishing that references your real name, address and a recent order. Treat unexpected emails, texts or calls about your orders as suspicious.

Who is behind the Ceva Logistics cyberattack?

As of August 10, 2026, no group or ransomware crew has been publicly tied to the attack. Ceva has not said whether anyone demanded money, and the Dutch Data Protection Authority and other agencies are looking into it.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.