The CEVA Logistics breach, and why your shop is writing to you
One break-in at a warehouse operator, and letters went out to customers of a games company, a marketplace, a department store, an eyewear brand, a football club and a bank. Here is what was in the file, what was not, and the message you should expect next.
CEVA Logistics, the contract logistics provider that stores and packs orders for a long list of European brands, was broken into between 29 July and 1 August 2026. What came out is delivery paperwork: name, street address, postcode, city, country, phone number, the email on the order and what was bought. No passwords and no card numbers were involved, so there is nothing here to reset. The realistic risk is a delivery-themed message that quotes your real order back at you, and the defence is to check every order from inside the retailer’s own site or app instead of through a link.
Companies that have notified customers
What each company has said about its own customers, as reported between 10 and 14 August 2026. The list is not final: CEVA’s clients are still working out whose orders sat in the affected warehouses, so notices have been arriving in waves.
| Company | Who was written to | What the notice describes |
|---|---|---|
| Valve (Steam hardware) | European buyers of Steam hardware | Name, street address, postcode, city, country, phone number, email address, plus the type and price of the hardware ordered. Valve says it learned of the theft on 7 August and began writing to affected buyers on 10 August. |
| Bol | Customers of the Dutch marketplace | Names, addresses, postcodes, phone numbers, email addresses, order numbers, tracking information and purchase details. Bol says some records could also contain the message written on a gift card. |
| De Bijenkorf | Shoppers at the Dutch department store | Warned customers about delays and possible exposure of the details attached to their deliveries. |
| Ace & Tate | Eyewear customers | Named in press reporting as one of the retailers whose customer shipping details were caught in the same incident. |
| Ajax | The club’s shop customers | Reported by Dutch media as affected; the exposure again concerns delivery details rather than logins. |
| ING | Bank customers who were sent physical items | Reported as affected. A bank in this list does not mean bank systems were touched — what sits at a logistics provider is the address a card or a device was posted to. |
Sources: Valve’s customer notice and reporting by BleepingComputer, TechCrunch, The Record, The Register, Infosecurity Magazine and SecurityWeek, 10–14 August 2026. CEVA has not published a public statement of its own.
1. What happened, in order
Between 29 July and 1 August 2026 somebody got inside the systems of CEVA Logistics, one of the largest contract logistics operators in the world. On 1 August the company told the corporate customers it works for that a cyber intrusion was affecting part of its European contract logistics business, and said no other CEVA systems globally were involved. Eight European warehouses were disrupted over that weekend, which is why the first thing many shoppers noticed was a delayed parcel rather than a security notice. Valve was told on 7 August that data had been taken and started writing to buyers of Steam hardware on 10 August; the Dutch retailers went out to their own customers over the same days. CEVA itself has published nothing publicly and did not answer reporters who asked, so everything known about the scope comes from the companies it ships for.
2. Why the shop is writing to you, not CEVA
Most retailers do not own the building your order was packed in. Under a contract logistics arrangement the provider holds the stock, picks and packs the orders and hands them to a carrier, all under the retailer’s name, and the only data it needs is the paperwork of a delivery. That structure explains both the spread and the shape of this incident: a single intrusion touches customers of a marketplace, a department store, an eyewear brand, a football club, a bank and a games company at once, and none of those customers has any relationship with the company that was actually breached. It also means there is no CEVA account to log into, no page where you can type your name and see whether you are on the list, and no way to find out except from the business you bought from.
3. What was taken, and what was not
Across the notices published so far the same fields recur: full name, street address, postcode, city and country, phone number, the email address attached to the order, and what was ordered, sometimes with the price and the order or tracking number. Bol added that a few records may carry the message someone wrote on a gift card. What is absent from every notice is equally consistent: no passwords, no login credentials, no payment card numbers. That absence is the useful part of this story. Nobody can sign in as you with a packing list, so the resets and security checks that follow a normal account breach do not apply here. What they can do is speak to you as if they were the company you bought from, which needs no password at all.
4. The message to expect, and why it will sound right
A delivery lure works on anyone who is waiting for a parcel, and this file tells the sender exactly who is. Expect a text or an email about a problem with your delivery, a small customs or redelivery fee, an address that “could not be confirmed”, or a refund for an order that really did go wrong. It will quote the item you bought, the price you paid and the address it went to, because whoever holds the data can read all three. That accuracy is the trap: most people check whether a message knows them rather than how it reached them. Treat the details as public from now on, and judge every message by the route instead. Open the retailer’s app or type its address yourself, and look at the order there. Real problems with a real order are always visible in your own account.
5. What is worth doing this week
Four things, in order. Check the orders you are waiting for from inside the retailer’s own site or app rather than through any link. Turn on two-factor authentication for the mailbox tied to those orders, since the email address is now circulating next to your name, phone number and home address. Ask the retailer, in writing, what of yours was in the file and whether it has reported the incident to its data protection authority. And keep a note of the date the notice arrived, because a claim or a complaint made months later works better with a paper trail. Nothing on this list needs a password change, which is the unusual part of a breach like this one.
6. The part that outlives the incident
A leaked address is not undone by a notification. The same name, phone number and street address that came out of this warehouse are already published by people-search and data-broker sites, which is where the next round of target lists gets built regardless of who is breached next. Getting those listings taken down is the only step here with an effect that lasts past this news cycle, and it needs re-checking rather than doing once, because brokers re-list from public records within weeks. If you want the shorter version of the response to any breach, our post-breach guide covers it in seven steps, and the notification-letter guide explains how to read what a company sends you.
See what else is published about you
The address and phone number in that packing list are also sold by 499 broker and people-search sites, and those listings outlive any single breach. PersProtect finds where you are listed, files the removals and keeps checking that they stay down. The scan is free.
Check my exposure — free →The CEVA breach, answered
I got an email from a shop about a breach at their logistics provider. Is it real?
Several companies did write to customers in the first half of August 2026, so a message like that can be genuine. Do not judge it by how it looks, because the people holding the stolen file can write a better one. Open the retailer’s site or app the way you normally would, without touching the link, and look for the same notice there or in your account messages. If it exists, it will be published on their own site; if it does not, you have just spotted a phishing attempt built on the news.
Did my password leak in the CEVA breach?
No, and there is nothing here to reset. A contract logistics provider gets the details needed to pack and deliver a parcel: who you are, where it goes, how to reach you if the driver cannot find the door, and what is in the box. Passwords and login credentials never travel to the shipper, which is why the notices from Valve, Bol and the others talk about contact and order data instead. The risk is somebody using those details to sound like the company you bought from.
Were card numbers involved?
Nothing reported so far includes payment card numbers, and a shipper has no reason to hold them: the card is processed by the retailer and its payment provider, and the parcel label carries an address instead. What did come out in several of the notices is the price and the type of item ordered, which is enough for a convincing “problem with your payment for order 4471” message even without a real card number behind it.
Why does a company I have never heard of have my address?
Because most retailers do not run their own warehouses. Contract logistics means a provider like CEVA stores the stock, packs the orders and hands them to a carrier under the retailer’s name, which is how one break-in reaches customers of a marketplace, a department store, an eyewear brand, a football club and a games company at the same time. You have no relationship with them, no account there and no way to check yourself, which is exactly why the notification has to come from the shop.
Nobody has written to me. Am I in the clear?
Not necessarily, and not yet. Each of CEVA’s clients has to work out which of its own orders sat in the affected warehouses before it can write to anyone, so the notices have been arriving in waves rather than all at once, and the list of named companies has grown every few days. If you had something delivered in Europe over the summer from a retailer that outsources its fulfilment, treat delivery messages with suspicion for the next couple of months whether or not a letter arrives.
What are my rights if my data was in it?
In Europe you can ask the company that sold you the goods for a copy of what it holds and what it knows about the incident, and you can complain to your national data protection authority if the answer is thin. Valve said it was notifying the authorities in the countries affected, which is the normal path here. Compensation claims are a separate track that lawyers and regulators drive, and they take months; nothing you receive by email in the meantime asking you to “register your claim” is part of it.
Is this the same thing as my Steam account being hacked?
No. If you got the Valve email, your Steam account, password and Steam Guard are untouched, because none of that was ever at the shipper. Our Steam page has the full breakdown of that notice and the account-recovery steps for people who arrived there with a genuinely hijacked account instead.
Your address was already easy to find
A breach adds one more copy of it. See which sites publish your name, address and phone number right now — free, in about a minute.
Run my free exposure scan →