Eight European warehouses were knocked offline by a July 29 attack on CEVA Logistics, which is still working to restore service. The CMA CGM Group subsidiary, active in more than 170 countries, informed customers on August 1 that goods held at those sites could not be dispatched.
CEVA has disclosed few technical details and named no attacker, and no ransomware crew has claimed the operation. Reports from The Register say customer information belonging to clients including Valve and Ajax was swept up. Valve confirmed that payment details, passwords, and Steam Guard codes never left its control, yet still urged customers to be wary of phishing that weaponizes the stolen data.
De Bijenkorf, a Dutch retailer caught in the incident, said the exposed records may cover names, addresses, emails, phone numbers, and order details, with payment data untouched.
For security teams, the episode is a reminder that logistics partners sit inside the supply chain trust graph. Firms doing business with CEVA should audit recent supplier messages for impersonation and assume any shared order data is in the wild.
