CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments
CEVA Logistics Cyberattack 🚨
CEVA Logistics suffered a cyberattack on July 29 that disrupted parts of its European operations. The incident impacted eight warehouses, and the company is still working to restore impacted services. On August 1, CEVA notified affected customers that goods stored at the disrupted facilities could not be shipped, highlighting the attack’s direct impact on logistics and supply chain operations.
The company did not disclose technical details about the attack or the threat actor behind the incident. At this time, no ransomware group has claimed responsibility.
Customer Data Exposed 🔓
The Register reported that the attack exposed customer data linked to major clients, including Valve and Ajax. Valve stated that payment details, passwords, and Steam Guard codes were not exposed because CEVA does not have access to them. However, the stolen customer data could still be used by cybercriminals to craft convincing phishing campaigns. Valve warned users to be cautious of suspicious emails or messages that may exploit information obtained in the breach to impersonate trusted services and trick victims into revealing sensitive information.
Personal Information at Risk ⚠️
Some affected organizations warned that personal information may have been exposed, in addition to the delays affecting order shipments. The Dutch premium department store chain De Bijenkorf, which was also impacted, reported that the security breach may have exposed names, addresses, email addresses, phone numbers, and online order details. No financial data was impacted. The company reported:
- Name and contact details, such as email address, address, and telephone number.
- Data regarding online orders, such as products, prices, discounts, delivery information, and a description of the payment method used.
- For business customers, the company name and VAT number may also be involved if these have been entered in My Account.
Additionally, in November, a hacker reportedly offered the company’s database for sale on a dark web marketplace, claiming it contains customer lists, shipping records, contracts, pricing information, and banking details. Such data could enable fraud, impersonation, and attacks against global supply chain operations.