The Ceva Logistics cyberattack has disrupted shipments for European retailers and created a customer-data exposure problem that now reaches Valve’s Steam hardware business. The attack affected at least eight European warehouses, Ceva told TechCrunch, though the company has not publicly set out the full scope, the affected sites, or the attacker’s identity.
The practical fallout is the familiar third-party breach mess: retailers hand a logistics provider enough data to fulfill an order, and a compromise at that provider can delay packages while putting contact and delivery records at risk. The known impact is limited to warehouse and contract-logistics operations in the reporting so far. It does not establish a disruption across all of Ceva’s business.
Which retailers were affected by the Ceva Logistics cyberattack?
Dutch online retailer Bol said it was told about the incident on August 1. According to reporting on Bol’s customer notice, intruders accessed two Ceva systems used to process orders from one of Bol’s distribution centers, not Bol’s own systems.
Bol temporarily removed products held at affected locations from sale, and said some orders were delayed or canceled. It also suspended data exchanges with Ceva while the companies assessed when they could restart them safely.
The potentially exposed Bol records included names, addresses, postal codes, phone numbers, email addresses, order numbers, tracking information and purchase details, according to the notification described by The Record. Some records may also have contained messages attached to gift cards. That is a list of data that may have been viewed or copied, not confirmation that every record was taken.
De Bijenkorf told customers that a cyberattack affecting one of its logistics providers had delayed orders, returns and refunds and could have exposed customer data. Ace & Tate and Ajax, whose merchandise and online orders Ceva handles, were also reported as affected.
What does the Ceva breach mean for Steam customers?
Valve began notifying European customers who bought physical Steam hardware. In the customer notice reproduced by Digital Foundry, Valve said the attack occurred between July 29 and August 1, and that it learned of the incident on August 7. Ceva receives delivery data to ship the products and can retain it for up to 90 days after an order, Valve said.
Valve could not determine exactly which customer records attackers obtained, so it notified people it considered reasonably likely to be affected. The potentially compromised fields were a customer’s name, street address, postal code and city, country, phone number, Steam-account email address, and the type and price of the hardware ordered.
Valve said Ceva does not have payment-card information, Steam passwords, Steam Guard codes, or information about other Steam purchases, and said customers did not need to change their Steam password or account settings on the basis of this incident.
- Expect unsolicited emails, texts or calls that claim to be from Steam, Valve or a delivery firm and cite a hardware order or address.
- Valve advised recipients to treat those approaches as fraudulent, including messages requesting a redelivery fee, customs payment, login, password or Steam Guard code.
- Use Steam’s official support site or type a known Steam address directly rather than following a link in an unsolicited message.
What remains unknown?
Ceva has not publicly identified the affected warehouses, the number of people or records involved, or which records were actually accessed or copied. There is also no public attribution for the intrusion, and no confirmed information on the attack method, ransomware use, or an extortion demand. Valve said Ceva had isolated the affected systems, taken them offline and brought in outside investigators, while Valve sought more detail and began notifying data-protection authorities.
This story draws on original reporting from The Record.