Ceva Logistics cyberattack compromises data of Valve, ING, and major Dutch retailers
The France-headquartered logistics provider, which reported $18.3 billion in revenue for 2025, confirmed a cyber intrusion beginning on 29 July that has disrupted operations and triggered investigations by Dutch authorities.

A cyberattack on Ceva Logistics has compromised the personal data of customers belonging to several high-profile corporations, including video game company Valve, banking group ING, and Dutch retailers Bol and De Bijenkorf. The incident, which began on 29 July, has resulted in shipping delays at eight European warehouses operated by the logistics giant. Ceva confirmed the intrusion and stated that its cybersecurity teams activated security protocols and launched an investigation, while authorities in the Netherlands examine the breach.
Ceva Logistics, a France-headquartered shipping and logistics provider that generated $18.3 billion in revenue in 2025, operates over a thousand warehouses globally. The company serves as a critical link in the supply chain for businesses delivering goods from assembly lines to customer homes. Industry reports indicate that the hack has caused significant shipping delays for goods within the affected European facilities. The operational impact is currently confined to these eight warehouses, with Ceva asserting that all other global operations continue without incident.
The breach has exposed personal information, including names, addresses, phone numbers, and email addresses, used to place orders. Dutch online retailer Bol warned that customers’ data may have been taken and expects delays and order cancellations. Luxury retailer De Bijenkorf similarly confirmed order delays following the theft of customer data. Football club Ajax, eyewear maker Ace & Tate, and banking group ING also reported that customers’ shipping information was affected by the intrusion.
Valve, the video game company, alerted customers on 7 August that data had been taken from Ceva’s systems. The company specified that the breach affects customers who recently purchased Steam hardware. Valve noted that Ceva stores shipping and delivery information for 90 days following an order. The company advised customers to treat any unsolicited communications claiming to be from Steam, Valve, or delivery services as fraudulent, warning that malicious actors may quote addresses back to victims to appear genuine.
Ceva spokesperson Ryan Fisher declined to answer questions regarding the volume of personal data taken or if the company received any communication from the hackers, such as a ransom demand. The company stated that some affected applications and services are back online and that it is working with authorities. Ceva’s website was not properly loading at the time of publication on Monday. Mark Schenkel, a spokesperson for the Dutch data protection authority, did not respond to requests for comment.
