When a cyber intruder slipped into Ceva Logistics’ European warehouses last month, the ripple reached some of the continent’s most recognizable brands.

Between July 29 and August 1, 2026, an intrusion hit eight of Ceva’s contract‑logistics sites across Europe, according to Dutch media and industry observers. Shipping schedules stalled for several high‑profile retailers, and personal and order information belonging to customers of Valve’s Steam hardware shipments may have been exposed.

Ceva Logistics, a French‑based freight and supply‑chain company that operates more than 1,700 facilities worldwide and employs roughly 110,000 people, has not issued a public statement about the breach. The company reportedly notified corporate clients earlier in the month that a cyber intrusion was affecting part of its contract‑logistics business.

FreightWaves, citing a source familiar with the investigation, said that no Ceva systems beyond those warehouses were impacted. Air, ocean, ground and rail transportation management operations continued without disruption.

Retailers that have confirmed the impact include Dutch e‑commerce giant Bol, luxury department store De Bijenkorf, eyewear retailer Ace & Tate, and Dutch football club Ajax, whose merchandise and online orders are handled by Ceva. Bol discovered that cybercriminals had accessed two Ceva systems used to process orders from one of its distribution centers. The breach did not affect Bol’s own IT systems.

Because products stored at the affected locations were temporarily taken offline, Bol experienced delays and cancellations of some customer orders. The company suspended data exchanges with Ceva as a precaution and said it would resume them only when it was safe to do so. Bol also notified affected customers that information stored in the compromised Ceva systems at the time of the attack—including names, addresses, postal codes, telephone numbers, email addresses, order numbers, tracking information, purchase details and gift‑card messages—may have been viewed or copied by unauthorized parties.

De Bijenkorf warned its customers last week that a cyberattack on one of its logistics providers had caused delays to orders, returns and refunds and could have exposed customer data. Ajax and Ace & Tate have also confirmed that their shipments were impacted.

Valve, the U.S. video‑game company behind the Steam platform, began notifying European customers on Monday that information associated with purchases of physical Steam hardware may have been compromised. Ceva receives delivery information from Valve and can retain those records for up to 90 days after an order. Valve said it could not determine precisely which records the attackers obtained and therefore notified customers whose information it could reasonably assume may have been affected.

The potentially compromised data includes customers’ names, street addresses, postal codes, cities, countries, telephone numbers and email addresses, as well as the type and price of Steam hardware they ordered. Valve said it was pressing Ceva for the full scope of what was taken and was in the process of notifying data‑protection authorities in the affected countries.

No public attribution for the attack has been announced, and it remains unclear whether ransomware was deployed or whether the hackers made an extortion demand. Ceva Logistics has not disclosed the identity of the attackers.

The incident highlights the vulnerability of third‑party logistics providers to cyber threats. While Ceva’s core transportation operations were unaffected, the disruption of its warehouse systems has had a cascading effect on the supply chains of several high‑profile European retailers and on the delivery of Steam hardware to customers across the continent.

Ceva Logistics is a subsidiary of the CMA CGM group, a French shipping and logistics company that acquired the former Bolloré Logistics in 2024 and rebranded it under the Ceva name. The company’s headquarters are in Marseille, France.

At this time, Ceva has not released a statement, and it is unclear what remedial actions the company will take or whether it will cooperate with law‑enforcement investigations. The incident has prompted affected customers to pause data exchanges and to monitor for potential phishing or fraud attempts that could exploit the exposed information.

The situation remains fluid. Stakeholders are awaiting further details from Ceva, from law‑enforcement agencies, and from the affected retailers and Valve regarding the full scope of the breach, any potential ransom demands, and the steps being taken to secure customer data and restore normal warehouse operations.