One Vendor, Eight Warehouses, Ten Companies
CEVA Logistics, a France-based shipping and logistics company that reported $18.3 billion in 2025 revenue, disclosed that a cyberattack beginning July 29 disrupted operations across eight of its European warehouses. CEVA confirmed the intrusion on August 1, stating that its cybersecurity teams activated incident response protocols immediately and launched an investigation that continued for weeks afterward. The company was careful to note that the disruption stayed contained to those eight facilities and that its other global operations continued without incident, a distinction that matters operationally but did little to limit the data exposure once downstream companies began notifying their own customers.
By mid-August, ten organizations had reported the breach to the Dutch data protection authority, spanning industries that share nothing except a CEVA shipping relationship: Bol and De Bijenkorf, two major Dutch retailers, football club Ajax, banking giant ING, eyewear brand Ace and Tate, and Valve's Steam gaming platform. Valve disclosed that CEVA retains shipping data for ninety days following an order, which is the detail that explains why a logistics breach reached a video game company's customer records at all: physical goods shipped through CEVA carried customer data with them into a system none of those customers ever directly interacted with.
What Actually Leaked
The data exposed across affected organizations followed a consistent pattern: customer names, home addresses, phone numbers, email addresses, and shipping or delivery information. De Bijenkorf's disclosure added a business-customer wrinkle, noting that company names and VAT numbers were exposed for its commercial accounts alongside the standard consumer data categories. None of the disclosures so far describe payment card data or passwords as part of the exposure, which limits the most severe fraud pathways, but the combination of full name, home address, and phone number is still more than enough to fuel convincing targeted phishing and delivery-scam campaigns against real customers.
CEVA has not published technical detail about how the attackers gained initial access, and the investigation remained open weeks after the intrusion began. What is public is the operational fallout: shipping delays across the affected warehouses and order cancellations reported directly by both Bol and De Bijenkorf, meaning customers experienced the breach twice, once as a service disruption and again as a data exposure notification arriving separately, often through the retailer they actually shop with rather than through CEVA itself.
Why This Kind of Breach Is Hard to See Coming
The structural problem this incident illustrates is that logistics vendors sit in an unusual position in the data supply chain. A retailer's own security team can audit its website, its payment processor, and its cloud infrastructure with real confidence. It has far less visibility into what a shipping partner does with the customer data handed over for delivery, how long that data sits in the vendor's systems after the order completes, or what the vendor's own security posture looks like at the warehouse and systems level. Valve's disclosure that CEVA retains shipping data for ninety days is the kind of retention detail that most retailers using a shared logistics vendor likely could not state confidently about their own arrangement before this incident forced the question.
That visibility gap is not unique to CEVA or to logistics specifically. It is the same problem every enterprise has with any vendor that receives customer data as a normal part of doing business, from payment processors to marketing platforms to, in this case, the company that physically delivers the product. The difference with logistics is that the data handoff feels so operational and so far from anything security teams typically monitor that it rarely gets the same vendor risk scrutiny a SaaS integration or a payment processor would receive during procurement.
The Vendor Risk Decision This Forces
Every enterprise that outsources fulfillment or last-mile delivery, which by now includes most retailers of any meaningful scale, should treat this incident as a prompt to answer a specific question they may not currently have documented: exactly what customer data does each logistics vendor hold, in what format, for how long after an order completes, and under what security controls. The ninety-day retention window Valve disclosed for CEVA is a reasonable industry norm, but reasonable does not mean risk-free, and most procurement processes for logistics vendors focus on delivery performance and cost rather than data handling practices.
The follow-up question, and the harder one, is what breach notification obligation your own organization carries when a vendor holding your customer data gets breached instead of you. Regulatory frameworks across the EU and increasingly in the US treat this as the customer-facing company's responsibility regardless of where the actual intrusion happened, which is exactly why ten separate organizations ended up filing notifications with Dutch regulators over one CEVA incident. If your logistics contracts do not specify a notification timeline the vendor owes you when this happens, that gap needs closing before it gets tested by an incident rather than a negotiation.
What to Do This Quarter
Start with an inventory exercise that most security and procurement teams have never formally completed: list every logistics, fulfillment, and delivery vendor with access to customer data, and for each one, document what data they hold, how long they retain it, and what breach notification clause exists in the current contract. If any of those fields come back blank, that vendor relationship carries more unmanaged risk than most SaaS vendors on the same procurement list, simply because logistics has historically been evaluated on operational metrics rather than data security ones.
For contracts up for renewal, add specific retention limits, since a shorter retention window directly shrinks the blast radius of any future breach at that vendor. Add a notification timeline measured in days, not weeks, and require confirmation of the vendor's own incident response capability as part of the renewal process rather than treating it as a one-time onboarding checkbox. CEVA's incident will not be the last logistics breach to ripple across a shared customer base, and treating this review as a recurring exercise rather than a one-time fire drill is what separates the organizations that absorb the next one quickly from the ones still filing notifications months later.


