Ceva Logistics disclosed a data breach affecting its European contract logistics operations, with eight warehouses compromised between July 29 and August 1, 2025. The company, a subsidiary of CMA CGM Group (the world's third-largest shipper), notified affected customers on August 1. The breach impacted the division responsible for warehousing, fulfillment, manufacturing support, and aftermarket services, while other global operations remained unaffected.
Attackers accessed delivery-related information that Ceva retains for up to 90 days after orders are fulfilled. According to notifications sent by affected clients, the compromised data includes customer names, email addresses, home addresses, phone numbers, and order details. Gaming company Valve informed its European hardware customers about the breach, explaining that Ceva receives specific delivery information from Steam to ship physical products.
The breach affected multiple high-profile European clients beyond Valve. Dutch online retailer Bol reported that restoration of operations at Ceva's Veerweg location is taking longer than expected, potentially impacting service levels. Other affected organizations include Dutch department store chain De Bijenkorf, football club Ajax, and banking institution ING. The incident highlights the cascading impact of supply chain security failures on downstream customers.
Security researchers emphasize that logistics companies represent attractive targets because they process thousands of transactions and hold contextual information about people and products. The combination of names, addresses, contact details, and recent purchase information provides attackers with sufficient context to craft convincing phishing and impersonation attempts. This makes the stolen data particularly valuable for follow-on social engineering attacks.
Security experts recommend that affected customers treat any unexpected delivery-related messages as potentially malicious. Rather than clicking links in emails or paying fees requested through unsolicited messages, customers should navigate directly to official retailer websites by manually typing addresses. Organizations that depend on third-party logistics providers should treat these vendors as part of their security perimeter, recognizing that they can become points of failure even when not the primary target. CMA CGM previously experienced a ransomware attack in 2020 that temporarily shut down its shipping website and applications.
Source: https://www.infosecurity-magazine.com/news/logistics-ceva-data-breach/


