A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
- ID
- 12680
- Status
- summarized
- Published
- 10 Aug 2026, 10:20 PM
- Fetched
- 10 Aug 2026, 10:25 PM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 5.5
- Created
- 10 Aug 2026, 10:27 PM
- Tags
- Audience
- developerssaas_founders
What happened
Ceva Logistics, a France-headquartered shipping giant with $18.3B revenue and over 1,000 warehouses, was hacked starting July 29, affecting at least 8 European warehouses and causing shipping delays. Customer personal data (names, addresses, phone numbers, emails) was stolen for clients including Bol, De Bijenkorf, Ajax, ING, Ace & Tate, and Valve/Steam, with Valve notifying customers on August 7.
Why it matters
If you ship physical goods through third-party logistics providers, this is a concrete reminder that your customer PII lives in systems you don't control — and that a breach at your warehouse partner becomes your breach notification problem. Review what customer data your fulfillment or shipping vendors can access and whether you're contractually obligated to notify customers when that vendor is compromised, as Bol and Valve had to do here.
Discussion angle
How much customer PII do you actually need to hand to your shipping/fulfillment partner, and could you reduce exposure by tokenizing or minimizing the data passed downstream — or is the industry structurally stuck passing full names and addresses?