< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 53 sources · 5 days · First seen · Last updated

CEVA Logistics cyberattack and data breaches

Overview

A cyberattack targeting the third-party logistics provider CEVA Logistics resulted in data breaches affecting multiple international clients. The intrusion, which occurred between July 29 and August 1, 2026, involved unauthorized access to systems at a distribution center.

Initially, the breach was linked to Dutch retailers Bol.com and De Bijenkorf. Exposed customer information included names, addresses, contact details, and order-related data such as product types and prices. While payment credentials and passwords remained secure, the retailers faced operational disruptions, including order delays and halted data exchanges.

Following the initial reports, Valve confirmed the breach on August 7, identifying that it also impacted Steam hardware buyers. Because CEVA retains delivery-related information for up to 90 days, the breach likely affects anyone in Europe who ordered Valve hardware—such as the Steam Deck, Steam Machine, or Steam Controller—within that timeframe. Compromised data includes full names, physical addresses, postal codes, cities, phone numbers, email addresses linked to Steam accounts, and product order details.

Valve emphasized that sensitive account credentials, such as passwords, payment information, and Steam Guard codes, were not compromised because CEVA Logistics does not have access to that data. Valve has notified relevant data protection authorities and warned that the stolen data could facilitate phishing scams involving fraudulent requests for customs fees or delivery confirmations. Valve is currently pressing CEVA for a full investigation into the scope of the attack. CEVA Logistics has since isolated the affected systems and engaged cybersecurity specialists to investigate the incident.

Entities

CEVA Logistics · De Bijenkorf · Steam · Steam Machine · Autoriteit Persoonsgegevens

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

Timeline

  1. 2 days ago

    [TECHNOLOGY] 42 sources
    CEVA Logistics cyberattack exposes European Steam hardware customer data

    A cyberattack on CEVA Logistics has exposed personal data and order details of European Steam hardware customers, prompting Valve to warn users of potential phishing scams.

  2. 7 days ago

    [TECHNOLOGY] 12 sources
    Bol.com and De Bijenkorf breach after CEVA Logistics cyberattack

    A cyberattack on CEVA Logistics exposed personal data of Bol.com and De Bijenkorf customers, causing order delays and cancellations; retailers’ own systems were unaffected and the breach was reported to Dutch‑​

Sources

1001infos.net · 1001web.fr · analyticsinsight.net · apach57.fr · armichiwellness.com · blogspan.net · bright.nl · bug.hr · chiccheinformatiche.com · computable.nl · countryrebel.com · dawn.fi · diarioestrategia.cl · dutchnews.nl · e.sport.interia.pl · flo.com · fr.ign.com · gamerbrain.net · gamereactor.fr · gamerfocus.co · genderandhealth.org · gram.pl · igorslab.de · kitguru.net · kurierverlag.de · mannheim24.de · me.ign.com · netthings.pt · nieuws365.be · nosmokesport.com · nrsgamers.it · omroepbrabant.nl · pcpowerplay.com.au · play3.de · pt.ign.com · quartieri.vicenzapiu.com · rayhaber.com · senioractu.com · techjuice.pk · telepolis.pl · thecyberexpress.com · thegeek.games · thenextweb.com · thepostonline.nl · therecord.media · theregister.co.uk · tomshardware.fr · tribuna.com.mx

This summary has been updated 3 times: see revision history