Between 29 July and 1 August 2026, a cyberattack disrupted operations across eight European warehouses operated by Ceva Logistics (Ceva), the France-headquartered contract logistics business owned by the CMA CGM Group. Ceva confirmed the intrusion to affected customers on 1 August, activated its cybersecurity protocols, and opened an investigation that continues as this is written. The company has not disclosed how attackers reached its systems, and no ransomware group or extortion actor has publicly claimed the attack.
The compromise reached order processing systems used across the affected warehouses. From there, attackers took names, home addresses, phone numbers, email addresses, order details and VAT numbers belonging to the customers of the retailers and brands that rely on Ceva to fulfil their deliveries. Dutch online retailer Bol and luxury department store De Bijenkorf both warned customers that shipping data may have been exposed. Banking group ING, football club Ajax, eyewear retailer Ace & Tate, and video game company Valve each separately confirmed that customer information handled through Ceva's systems had been affected, with Valve telling Steam hardware buyers on 7 August that shipping and delivery details it holds through Ceva for 90 days after purchase had been caught up in the breach.
None of those organisations were breached directly. Their customers' data left through a single shared supplier, exposed once and multiplied across every brand that supplier served. The Dutch data protection authority confirmed it had received breach notifications from ten separate organisations tied to the same incident, a figure that shows how concentrated the downstream exposure has become in contract logistics, an industry that holds other companies' customer data as a matter of course.
Ceva says the operational impact was contained to the eight affected warehouses and that its other operations, spanning air, ocean, ground and rail logistics for a company that generated $18.3 billion in revenue in 2025, continued without disruption. That containment does not extend to the data. Once personal records leave a warehouse's order system, no amount of network segmentation brings them back, and the retailers whose customers are now exposed to targeted phishing attempts had no visibility into, and no control over, the moment their supplier's systems were compromised.
The defences that failed here were not weak by conventional standards. Ceva restored affected applications within days, contained the intrusion to a subset of its systems, and is coordinating with the Dutch data protection authority and other regulators. What none of that addressed is the moment that actually mattered: whoever accessed those order processing systems, whether through a known vulnerability or valid credentials nobody had revoked, pulled bulk customer records out without a single confirmation step standing in the way. Vendor access of this kind gets treated as routine because it happens constantly. It is not routine. It carries the same blast radius as any other large data export, and it executed exactly like one.
A bulk export from an order processing system is an execution event. Before that export can complete, a confirmation request goes to Ceva's named security authority, on their registered device, over a channel the export request itself cannot reach. No confirmation, no export. It makes no difference whether the party attempting it arrived through a phished credential, an exploited application, or a valid account nobody had switched off. The control sits at the point where the data actually leaves, not at the point where an attacker first got in.
That distinction matters because Ceva, like most of its peers, has spent years hardening the perimeter around systems exactly like these. The perimeter held for every warehouse except eight. The control that would have held regardless of which eight, or which method got an attacker inside them, was never in place. Whoever reached those records, however they got in, cannot produce a biometric confirmation from a named authority on a device they do not hold. The execution boundary holds regardless of how the intrusion began.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References:
1. Whittaker, Z. 2026. A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond. TechCrunch, 10 August 2026.
2. FreightWaves. 2026. Cyberattack on Ceva Logistics warehouses in Europe impacts retailers. FreightWaves, 6 August 2026.
3. Rescana. 2026. Ceva Logistics Cyberattack Disrupts European Warehouses and Exposes Customer Data: Cybersecurity Incident Analysis. Rescana, 12 August 2026.
4. The Register. 2026. Cyberattack on logistics giant CEVA delivers customer data into the wrong hands. The Register, 11 August 2026.
