← CEVA Logistics

2026 CEVA Logistics — European warehouse intrusion Jul 29–Aug 1; Bol, Valve/Steam, Ajax, ING & more

2026 Unknown records affected Share on X

Data compromised

Customer shipping/fulfilment data held for client brands: names, addresses, phones, emails and order details commonly cited. Valve: names, addresses, phones, emails, product type/price for Steam hardware EU shipments (no Steam passwords, payment data, or Steam Guard). Dutch DPA told TechCrunch it received breach reports from 10 organisations tied to the incident. Aggregate headcount unpublished.

Technical writeup

Company-confirmed European logistics breach with multi-brand customer notifications — CEVA told TechCrunch (Aug 10, 2026) a cyber intrusion impacted part of its European contract logistics operations beginning around late July, with operational impact limited to eight warehouses; investigation ongoing with authorities. Valve’s Aug 10 customer emails state attackers accessed CEVA servers July 29–August 1 and likely took EU Steam hardware shipping data (names, addresses, phones, emails, product type/price) retained up to 90 days; Steam account credentials/payments not held by CEVA. Earlier client warnings include Bol, De Bijenkorf, Ajax, ING loyalty shop, and Ace & Tate. Dutch DPA spokesperson said 10 organisations filed breach reports related to the incident. recordsAffected remains 0 pending an attested census. Hub row now companyConfirmed true based on CEVA’s statement to TechCrunch.

Root cause

Cyber intrusion impacting part of CEVA’s European contract logistics operations (company statement to TechCrunch). Valve says attackers had access to CEVA servers between July 29 and August 1, 2026; operational impact limited to eight warehouses per CEVA.

References