< Back to situation

[REVISION HISTORY]

CEVA Logistics cyberattack and data breaches

Updated 3 times since CLSTR started tracking revisions of this situation.

What changed

2026-08-10 21:23 UTC → 2026-08-11 10:27 UTC · added removed

A cyberattack targeting the third-party logistics provider CEVA Logistics resulted in data breaches affecting multiple international clients. The intrusion, which occurred between July 29 and August 1, 2026, involved unauthorized access to systems at a distribution center. Initially, the breach was linked to Dutch retailers Bol.com and De Bijenkorf. Exposed customer information included names, addresses, contact details, and order-related data such as product types and prices. While payment credentials and passwords remained secure, the retailers faced operational disruptions, including order delays and halted data exchanges. Following the initial reports, Valve identified confirmed the breach on August 7 and notified customers 7, identifying that it also impacted Steam hardware buyers. Because CEVA retains delivery-related information for up to 90 days, the breach likely affects anyone in Europe who ordered Valve hardware—such as the Steam Deck, Steam Machine, or Steam Controller—within that timeframe. Compromised data includes full names, physical addresses, postal codes, cities, phone numbers, email addresses linked to Steam accounts, and product order details. Valve emphasized that sensitive account credentials, such as passwords, payment information, and Steam Guard codes, were not compromised because CEVA Logistics does not have access to that data. Valve has notified relevant data protection authorities and warned that the stolen data could facilitate phishing scams involving fraudulent requests for customs fees or delivery confirmations. Valve is currently pressing CEVA for a full investigation into the scope of the attack. CEVA Logistics has since isolated the affected systems and engaged cybersecurity specialists to investigate the incident.

Versions

  1. 2026-08-11 10:27 UTC CEVA Logistics cyberattack and data breaches
  2. 2026-08-10 21:23 UTC CEVA Logistics cyberattack and data breaches
  3. 2026-08-10 15:22 UTC CEVA Logistics cyberattack and data breaches
  4. 2026-08-10 12:54 UTC CEVA Logistics cyberattack and data breaches

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.