BusinessCybersecurityNewswireTechnology

Ceva Logistics Data Breach Hits European Clients

Originally published on: August 12, 2026
▼ Summary

– Ceva Logistics, a subsidiary of CMA CGM Group, suffered a data breach affecting its European contract logistics operations, with eight warehouses impacted and customers notified on August 1.
– The cyber-attack lasted from July 29 to August 1, and hackers may have accessed names, email and home addresses, phone numbers, and order details of customers, including those of video game developer Valve.
– Other impacted clients include Dutch online retailer Bol, department store De Bijenkorf, football club Ajax, and banking giant ING, with some facing service disruptions.
– Experts argue the logistics sector is a prime target because companies sit at the center of transactions, and shipping data can enable convincing phishing and impersonation attacks.
– Security advisors warn of a likely wave of “delivery problem” phishing lures following the breach, and note that CMA CGM previously suffered a ransomware attack in 2020.

A cyberattack on one of the world’s largest freight operators has sent ripples through its European client base, exposing sensitive customer information and raising fresh concerns about third-party risk in the supply chain sector.

Ceva Logistics, a subsidiary of France’s CMA CGM Group, the third-largest shipping company globally, confirmed that its European contract logistics division was the target of the incident. That branch of the business handles warehousing, fulfilment, manufacturing support, and aftermarket services for a wide range of corporate clients.

According to a short statement from the company, affected customers were alerted on August 1, with eight warehouses impacted by the intrusion. The firm was quick to emphasize that no other systems worldwide were compromised and that all remaining operations were running normally.

One of the most prominent victims is video game developer Valve. In an email forwarded to its own customers, Valve explained that the attack ran from July 29 through August 1. The company stated that Ceva holds delivery-related data from Steam, including names, email and home addresses, phone numbers, and order specifics, which the attackers likely accessed. Since Ceva retains that information for up to 90 days after a purchase, Valve reached out to every customer it believed could be affected.

The fallout extends well beyond the gaming industry. Dutch e-commerce firm Bol reported that service restoration at Ceva’s Veerweg facility is taking longer than expected, potentially delaying deliveries. Other impacted clients include department store chain De Bijenkorf, football club Ajax, and banking heavyweight ING.

Security experts argue that logistics firms have become prime targets for a simple reason: they sit at the crossroads of countless business-to-consumer transactions. Joseph Perry, cybersecurity researcher and advanced services lead at Arcova, noted that a breach in this sector can create operational chaos while handing attackers a trove of personal and transactional data. He pointed out that shipping information is highly contextual, giving criminals everything they need to craft convincing phishing schemes.

“A name, address, phone number, email address, and recent purchase can give attackers enough context to make phishing and impersonation attempts far more convincing,” Perry said. He urged companies to treat their logistics partners as extensions of their own security posture, warning that “you do not have to be the final target to become the point of failure.”

Anna Collard, CISO advisor at KnowBe4, described the incident as a textbook supply chain breach. She predicted a surge of fraudulent messages in the coming weeks, including fake delivery notices, redelivery fee requests, and order verification scams. Her advice to consumers is straightforward: treat any unsolicited message about an order as suspicious, avoid clicking links or paying fees, and navigate directly to the retailer’s official website.

This is not the first time CMA CGM has faced cyber trouble. In 2020, the parent company suffered a ransomware attack that forced the temporary shutdown of its shipping website and applications.

(Source: Infosecurity Magazine)

Topics

data breach 98% supply chain security 95% logistics industry 93% cyber-attack impact 92% customer data exposure 90% ransomware threats 88% phishing risks 87% third-party risk 86% incident notification 84% operational disruption 82%
Show More