Ceva Logistics Hack Exposes Customer Data Across Europe
3 min read
A cyberattack on global logistics company Ceva Logistics is disrupting shipments and exposing customer information for several major retailers and companies across Europe.
The attack, which began on July 29 according to industry publication FreightWaves, has affected at least eight Ceva warehouses in Europe. The company confirmed to TechCrunch that the incident is causing operational problems at those facilities, while shipments of some products are being delayed.
Ceva, headquartered in France, operates one of the world’s largest logistics networks. Businesses use the company to move products from manufacturers and warehouses to customers. Ceva generated $18.3 billion in revenue in 2025 and operates more than 1,000 warehouses around the world.
The incident is significant not only because of the shipping disruption, but also because hackers appear to have accessed personal information connected to customers of companies using Ceva’s services.
Several businesses have warned customers that information such as names, home addresses, phone numbers and email addresses may have been exposed.
Dutch online retailer Bol was among the companies to notify customers. The company said attackers gained access to systems belonging to Ceva, its warehousing partner, and that customer information may have been compromised. Bol also warned that the cyberattack could lead to shipping delays and the cancellation of some orders.
Luxury retailer De Bijenkorf also confirmed delays and reported that customer data had been affected, according to local media reports. Other organizations reporting an impact include Dutch football club Ajax, banking giant ING and eyewear company Ace & Tate.
The breach has also reached the gaming industry.
Valve, the company behind Steam, said it discovered on August 7 that information had been taken from Ceva’s systems. Valve subsequently contacted customers who had recently purchased Steam hardware and warned them that their personal information was involved.
In a message posted to Reddit, Valve explained that Ceva keeps shipping and delivery information for 90 days after a Steam hardware order is placed.
Valve spokesperson Doug Lombardi did not respond to a request for comment about the incident.
Ceva confirmed the cyberattack in a statement provided to TechCrunch. The company said it identified the intrusion on August 1 and informed affected customers that part of its European contract logistics operations had been impacted.
Ceva said its cybersecurity teams immediately activated security procedures and began an investigation that remains ongoing. According to the company, the operational disruption is limited to eight warehouses and no other Ceva systems worldwide were affected.
The company has not disclosed how much personal information may have been stolen. Ceva spokesperson Ryan Fisher also declined to answer questions about whether the attackers had contacted the company or demanded a ransom.
Some affected Ceva applications and services have already returned online, while the company says it is cooperating with authorities investigating the incident.
At the time of publication on Monday, Ceva’s website was also experiencing loading problems.
Authorities in the Netherlands are reportedly investigating the cyberattack. Mark Schenkel, a spokesperson for the Dutch data protection authority, did not respond to TechCrunch’s request for comment on Monday.
The incident highlights the growing cybersecurity risks facing logistics companies. These businesses are increasingly attractive targets because their systems can provide access to sensitive customer information while also controlling the movement of large volumes of physical goods.
For now, Ceva says its wider global operations remain unaffected, but the investigation into the European breach is still underway.
Also read : TechCrunch Disrupt 2026 Offers Final $100 Flash Discount
