Between July 29 and August 1, 2026, attackers breached Ceva Logistics' systems, stealing delivery data — names, addresses, phone numbers, and order details — from at least six major clients including Valve (Steam hard...
Research answer

Create a landscape editorial hero image for this Studio Global article: What happened in the July 2026 cyberattack and data breach at Ceva Logistics, which companies and customers were affected (including Bol, De. Article summary: ## July 2026 Ceva Logistics Cyberattack & Data Breach. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
A single cyberattack on a global logistics giant turned into a cascading data breach that touched retail giants, a major bank, a football club, and thousands of Steam gamers across Europe. Here is a clear, source-backed breakdown of what happened in the July 2026 Ceva Logistics incident.
On July 29, 2026, an unidentified attacker gained unauthorized access to order-processing systems at Ceva Logistics, a France-headquartered freight and contract logistics company owned by the CMA CGM Group . The intruder maintained access until August 1, affecting Ceva's European contract logistics operations — specifically, eight warehouses across the continent
.
Ceva notified its affected clients on August 1 that a "cyber intrusion" had disrupted operations at those sites, halting outgoing shipments .
None of the brands involved suffered a direct breach. Instead, all of them shared Ceva as a third-party fulfillment partner, making this a textbook supply-chain (or fourth-party) data incident. The Dutch data protection authority (Autoriteit Persoonsgegevens) received GDPR Article 33 breach reports from at least ten separate organizations . The confirmed list includes:
The attackers obtained delivery and order data that Ceva held to fulfill shipments. The exposed fields consistently reported across multiple news outlets include :
Multiple sources from TechCrunch, Bleeping Computer, and The Register confirm that financial data — including credit card numbers, bank account details, and login credentials — was not compromised, because Ceva never stored it . However, the exposure of contact and order data creates a heightened risk of targeted phishing and social engineering attacks, a point Valve explicitly warned its customers about
.
The cyberattack had a tangible physical impact. Ceva confirmed that shipments were halted or significantly delayed at the eight affected European warehouses . Ceva stated that no other systems globally were affected and that all other operations continued without interruption
. As of mid-August 2026, the company was still working to restore full operations at the impacted sites
. Some shipments were canceled, and delivery timelines remained uncertain
.
Ceva Logistics provided a limited public statement, which it shared with multiple news outlets. The company said :
"The operational impact is limited to eight warehouses. No other CEVA systems globally were affected, and all other operations continue without interruption."
Ceva also stated it could not rule out that personal data had been exposed and that the investigation was ongoing . The company declined to disclose technical details about the intrusion, and as of publication, no ransomware group had claimed responsibility
.
The Ceva breach is a stark reminder that a single vendor compromise can ripple across an entire ecosystem of trusted brands, turning a logistics failure into a widespread data exposure event.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Between July 29 and August 1, 2026, attackers breached Ceva Logistics' systems, stealing delivery data — names, addresses, phone numbers, and order details — from at least six major clients including Valve (Steam hard...