One Breach, Ten Apologies: What the Ceva Logistics Attack Teaches Every Company That Ships Anything
If you bought Steam hardware in Europe this summer, Valve sent you an uncomfortable email on Monday. Your name, home address, and phone number had been stolen — not from Valve, but from a French logistics company most gamers have never heard of.
That company is Ceva Logistics, a subsidiary of shipping giant CMA CGM that reported $18.3 billion in revenue in 2025, with about 110,000 employees across more than 1,700 facilities worldwide. Between July 29 and August 1, attackers had access to Ceva systems supporting its European contract logistics business. The company says the operational impact was limited to eight warehouses. By August 1, it was confirming to corporate customers that something was wrong.
Then the ripple started. Dutch online retailer Bol warned customers about delayed and canceled orders and possible data theft. Luxury department store De Bijenkorf reported delays to orders, returns, and refunds. Eyewear brand Ace & Tate and football club Ajax confirmed customer shipping data was affected, and Dutch media reported that ING customers' shipping information was exposed as well. The Dutch data protection authority told TechCrunch it has received breach reports from ten organizations over this single incident.
Ceva has issued no public disclosure. No attacker has claimed responsibility, and whether ransomware was deployed or a ransom demanded remains unknown.
The 90-Day Detail
Most breach notifications are boilerplate. Valve's contained a sentence worth rereading: Ceva "retains this information for up to 90 days after that order."
Valve hands Ceva exactly what it needs to deliver a package — name, address, phone number, email, what you ordered and what you paid for it. The delivery takes days. The data sits for three months. And when attackers got in, Ceva could not tell Valve precisely whose records were taken, so Valve notified every customer it "can assume" was impacted.
Valve learned about the theft on August 7 — six days after the attackers' access window closed. Every one of those days belonged to someone else's investigation.
In my experience, executives can usually name their top vendors. Almost none can say how long those vendors keep customer data after the work is done. The transaction ends. The data doesn't.
You Can Outsource the Warehouse, Not the Apology
Look closely at Bol's disclosure. According to the notification it sent customers, the attackers reached two Ceva systems that process orders for one of Bol's distribution centers. Bol's own network was untouched. Its customers still received warnings that names, addresses, order details — even messages attached to gift cards — may have been copied. Some orders were canceled outright, and Bol suspended its data exchanges with Ceva until it is satisfied the connection is safe.
Bol did nothing wrong in its own systems and still ended up apologizing to its customers. That is how third-party breaches work. Under European privacy law, the retailer that collected the data is typically the controller — the breach report carries its name, whoever's servers were actually compromised. Your customers don't parse the org chart of your supply chain. They ordered from you.
And this one cut twice. The same intrusion that exposed customer data also stopped warehouses — shipments delayed, some orders canceled outright. One event, two kinds of damage: regulatory and reputational through the data, revenue through the operations.
The Follow-On Attack Your Customers Will Face
Valve's notification included a warning that should be standard reading for any executive whose company ships products. Criminals holding this data, Valve wrote, may quote a customer's own address back to them to prove they're "genuine" — then ask them to confirm a delivery, pay a small redelivery fee, or verify an order through a fake sign-in page.
Stolen shipping data isn't an abstract privacy harm — it converts directly into convincing fraud against your customers, wearing your brand. The breach at your vendor becomes the phishing campaign against your buyers, and when it lands, the anger comes to you.
What to Ask Your CISO This Week
I've written about the Three Questions every executive should be able to answer — can we get hit, would we know, are we ready? A vendor breach stress-tests all three, because the answers live in someone else's building. Bring these to your next security briefing:
- Which vendors hold our customer data, and how long do they keep it after the transaction? Not the vendor risk register — the actual retention practice. If answering requires pulling the contracts, that is the finding.
- If our logistics or fulfillment partner went down tomorrow, how long could we keep shipping — and who tells our customers? Bol suspended data exchanges with Ceva as a precaution. Could you disconnect a compromised partner cleanly, or is the integration so deep that their incident is automatically yours?
- What do our contracts guarantee us in the first 72 hours after a vendor breach? Valve told customers it is "pressing" Ceva for the full scope of what was taken. Pressing is what you do when the contract didn't give you the right to demand. Notification deadlines and audit rights get negotiated before the incident, because you won't get them during one.
Eight warehouses went down, and ten companies had to explain it to regulators and customers. If your products move through someone else's warehouse, find out this week what else moves with them.