If you bought a game controller or a Steam Deck recently, your personal information may have been caught up in a shipping company's data breach.
Ceva Logistics, one of the world's biggest shipping and warehousing firms, got hit by a cyberattack in late July. Now the fallout is spreading to major retailers, Dutch banks, and even gamers who ordered hardware through Steam.
The Attack and the Fallout
The trouble started July 29, according to industry publication FreightWaves, and it quickly caused shipping delays at several European warehouses. On August 1, Ceva acknowledged the incident, informing affected clients that an unauthorized cyber intrusion had disrupted portions of its European contract logistics operations.
Contract logistics is a fancy way of saying Ceva runs warehouses and handles shipments for other companies. That is why the breach is rippling outward. Ceva's clients are the ones whose customer data was sitting in those systems.
Ceva stated that the operational disruption was confined to eight warehouses, and no other Ceva systems worldwide were impacted. But that is still a lot of packages. Ceva had 2025 revenue of $18.3 billion and runs over a thousand warehouses worldwide, making it one of the largest players in the shipping business.
Who Got Caught in the Crossfire
Hackers walked away with order-related personal data, including home addresses, email addresses, phone numbers, and customer names. That information is now a headache for a long list of companies.
Get the free Always Be Buying eBook and learn the simple system for building wealth on any income
Dutch online retailer Bol said customer information may have been exposed after hackers broke into Ceva, which handles its warehouse operations. Bol also warned customers about delayed and possibly canceled orders. Luxury retailer De Bijenkorf confirmed order delays after customer data was stolen, according to local media. Dutch companies Ajax, ING, and Ace & Tate also said their customers' shipment details were affected.
Then there is Valve, the company behind the Steam gaming platform. Valve told customers it found out on August 7 that data had been taken from Ceva systems. Valve's notice to customers on Reddit said Ceva keeps shipment and delivery data for 90 days after an order, which means the window of exposure is fairly recent but not tiny.
Dutch authorities are now investigating. The Dutch data protection authority has received breach notifications from 10 organizations tied to the incident, according to Mark Schenkel of that agency.
Why Shipping Companies Are in the Crosshairs
This is not just one unlucky company getting hacked. Shipping and logistics firms are becoming a favorite target for cybercriminals, and the reason is pretty straightforward.
Hackers can use access to trucks and containers to hand physical goods to real-world criminal groups. Stolen addresses and phone numbers are useful on their own, but the bigger prize is the logistics network itself. If you can break into the system that moves goods, you can redirect shipments, intercept deliveries, or sell that access to other criminals.
Ceva said it is cooperating with authorities and has restored some affected systems. The company declined to say how much data was taken or whether hackers made contact, including any ransom demand.
The bottom line: This breach shows how a single weak point in the supply chain can touch a huge number of people. Your data sits in a lot of places you never think about, and the company that delivers your package often knows as much about you as the store you bought it from.
For investors, the takeaway is about risk. Companies that handle logistics and shipping are essential to the economy, but they are also carrying a growing cybersecurity burden. A breach like this one can mean delayed shipments, angry customers, and legal trouble for everyone downstream. It is a reminder that when you own a piece of a company, you are also owning its weak spots.
The investigation is still ongoing, and more affected organizations could surface. For now, the best anyone can do is check for suspicious activity and keep an eye on those shipping confirmation emails.
Download the free Always Be Buying eBook and start putting your money to work today
