Cyberattack on CEVA Logistics Disrupts European Hubs, Leaks Client Data
A breach at the French logistics giant paralyzed eight warehouses and exposed customer data for Valve, Bol.com, and De Bijenkorf.
CEVA Logistics, a global freight and warehouse provider, suffered a targeted cyberattack on July 29 that paralyzed operations across eight of its European facilities. The incident caused widespread shipment delays and resulted in a significant data breach affecting several high-profile retail clients.
The attack disrupted the flow of goods through critical European hubs, leading to operational bottlenecks. The breach exposed sensitive customer data, including delivery and order information. Among the impacted clients were the e-commerce platform Bol.com, the department store De Bijenkorf, and Valve. Specifically, Valve issued warnings to European Steam hardware customers that their names, addresses, phone numbers, and order details may have been compromised as a result of the breach.
The Logistics Vulnerability
CEVA Logistics is a multinational French company owned by the CMA CGM group. As a primary third-party logistics (3PL) provider, CEVA serves as a critical link in the global supply chain, managing the movement and storage of goods for some of the world's largest brands. Because 3PL providers sit at the intersection of multiple corporate networks and consumer data streams, they have become high-value targets for threat actors seeking to disrupt commerce or harvest large datasets of personal information.
Systemic Supply Chain Risk
This incident underscores a growing systemic vulnerability within the global supply chain. When a single logistics partner is compromised, it creates a domino effect that extends far beyond the breached entity. In this case, the attack did not just halt CEVA's internal operations but directly impacted the customer experience and data privacy of thousands of consumers who had no direct contractual relationship with CEVA, but rather with the retailers they shopped with.
Gary Cannon, Global Transport Lead at NCC Group, noted that the attack disrupted warehouse operations across Europe and impacted customers of multiple organizations, highlighting how deeply integrated these logistics networks are with the broader retail ecosystem.
Looking Ahead
While the immediate operational disruptions have been documented, the full scale of the data exfiltration remains a point of concern. Industry analysts are watching to see if further clients will report data leaks and whether the attack was part of a broader campaign targeting the CMA CGM group's infrastructure. For now, the focus remains on the recovery of the eight affected warehouses and the notification of impacted consumers across the European market.