Ceva hack disrupts shipments and exposes customer data

At least eight Ceva warehouses in Europe were hit, causing order delays and exposing delivery details tied to retailers including Bol and Valve.
A cyberattack on Ceva Logistics has disrupted shipping in parts of Europe and exposed personal data tied to orders handled by the company. The breach matters not just because Ceva is a major logistics provider, but because the incident appears to have affected several brands that rely on it to get goods to customers.
The impact is already showing up in delayed orders, possible cancellations, and reports that customer contact details were taken from Ceva’s systems. As IT-PUB News reports, the case also points to a wider risk for online retail and delivery networks: when a logistics partner is hit, the damage can spread well beyond one company.
Eight Ceva warehouses in Europe were affected
Ceva Logistics told TechCrunch that the cyberattack is affecting at least eight warehouses across Europe used to ship goods around the continent. Industry outlet FreightWaves reported that the hack began on July 29 and has caused delays for many goods stored in the affected sites.
Ceva said the operational impact is limited to those eight warehouses. In its statement, the company said no other systems globally were affected and that all other operations continue without incident.
The company also said some affected applications and services are back online and that it is working with authorities. At the time of publication, Ceva’s website was not loading properly.
Even a limited disruption can ripple through supply chains at a company of Ceva’s size. The France-headquartered firm says it operates more than a thousand warehouses worldwide and brought in $18.3 billion in revenue in 2025.
Customer names and addresses were taken from order systems
The breach was not limited to shipping delays. Several companies said hackers also accessed personal information stored in Ceva’s systems for delivery purposes.
According to the source material, the stolen data included customers’ names, home addresses, phone numbers, and email addresses used when placing orders. In e-commerce, that kind of information is especially sensitive because it can be used to identify people, contact them directly, or connect them to specific purchases.
Dutch online retailer Bol said hackers gained access to systems of its warehousing partner, Ceva, and warned that customer data may have been taken. Bol also said it expects delays and that some orders may be canceled because of the incident.
De Bijenkorf, another Dutch retailer, confirmed order delays after the theft of its customers’ data, according to local media. Football club Ajax, banking giant ING, and eyeglass maker Ace & Tate also reported that customers’ shipping information was affected.
The case shows how much personal data is often shared with logistics providers, even when customers are buying from a retailer or brand rather than directly from a warehouse operator.
Valve alerted recent Steam hardware buyers
One of the more unusual names linked to the breach is Valve. The video game company said it learned on August 7 that data had been taken from Ceva’s systems and alerted customers who recently bought Steam hardware that their personal information had been involved.
Valve said in a note posted to Reddit that Ceva stores shipping and delivery information for 90 days after an order. That helps explain why a logistics breach can affect people who may not think of a warehouse as a place where their data is kept.
Valve spokesperson Doug Lombardi did not respond to a request for comment, according to the source.
The link between a shipping breach and gamers may seem unexpected. Still, it reflects a basic reality: delivery companies often hold the information needed to get a product from a warehouse to a front door, whether the buyer is ordering shoes, glasses, or gaming hardware.
Logistics firms are drawing more cybercriminal attention
Ceva’s breach comes as shipping and logistics companies face growing interest from cybercriminals. The source says these firms are attractive targets because attackers can potentially access and hijack trucks and containers to get goods into the hands of real-world gangs.
That makes logistics attacks different from many other data breaches. They are not only about stolen records — they can also interfere with the movement of physical goods, creating delays and operational uncertainty for businesses that depend on tight delivery schedules.
Ceva confirmed to TechCrunch that it was experiencing a cyberattack. The company said that on Aug. 1 it had confirmed to affected customers that a cyber intrusion was impacting part of its European contract logistics operations. It added that its cybersecurity teams activated security protocols immediately and launched an investigation that is still ongoing.
Ceva spokesperson Ryan Fisher did not answer questions from TechCrunch about how much personal data was taken or whether the company had received any communication from the hackers, including a ransom demand.
Dutch regulators received reports from 10 organizations
The incident has also drawn the attention of regulators. Authorities in the Netherlands are said to be investigating the case, and Mark Schenkel, a spokesperson for the Dutch data protection authority, told TechCrunch that the agency has received data breach reports from 10 organizations connected to the incident.
That suggests the effects of the attack extend beyond one logistics provider and into the businesses that depend on it. For customers, the immediate concern is whether their personal details were exposed. For companies, the problem is twofold: disrupted deliveries and the burden of explaining to shoppers why data held by a partner was compromised.
Ceva’s statement indicates that the company is still working through the incident, with some systems restored and the investigation ongoing. For now, the breach shows how quickly an attack on warehouse systems can turn into both a customer-data problem and a delivery disruption.