A cyberattack hit Ceva Logistics on July 29, knocking out eight European warehouses and halting shipments. The French-headquartered logistics giant told corporate client Bol about the intrusion on August 1 — but the notices that reached consumers came from the retailers themselves, not from Ceva.
Several major organizations confirmed impact, including Dutch retailers Bol and De Bijenkorf, ING, Ace & Tate, Amsterdam's Ajax football club, and game company Valve. Exposed data includes names, addresses, phone numbers, emails and order details.
De Bijenkorf said no payment details, IBANs, card data, usernames or passwords were involved; Ceva never held Steam payment credentials either. Valve says Ceva keeps order records up to 90 days, and has warned customers to expect fake emails, texts, and calls about their hardware orders.
Who's behind the attack remains unknown. Ceva has not publicly disclosed the incident, responded to press enquiries, or said how the intruders got in or how many people are affected.
Source: SecurityWeek