A cyberattack on international shipping giant Techcrunch has disrupted operations across eight warehouses in Europe and exposed customer data for a growing number of major brands, including video game giant Digital Foundry, Dutch e-commerce retailer Theregister, and department store De Bijenkorf.
Major Cyberattack Hits CEVA Logistics Warehouses Across Europe
The France-headquartered shipping and logistics company, which operates more than 1,000 warehouses worldwide and generated $18.3 billion in revenue in 2025, confirmed that the intrusion impacted part of its European contract logistics operations. According to notifications sent to affected partners, the cyberattack began between July 29 and August 1.
While Ceva’s air, ocean, ground, and rail transportation operations continued as normal, the security breach forced the company to isolate affected systems, take them offline, and bring in outside investigators. Ceva stated that the operational impact was limited to the eight European warehouses, and that no other systems globally were affected.
Impact on Steam Customers and Phishing Warnings
European customers who recently purchased Steam hardware—such as Steam Machines and Steam Controllers—were notified by Valve that their personal information was likely compromised in the incident. Valve learned of the breach from Ceva on August 7.

Because Ceva handles physical hardware fulfillment in Europe and retains delivery-related data for up to 90 days following an order, hackers were able to access specific shipping records. Valve stated that the compromised haul potentially includes:
- Customers’ names, street addresses, postal codes, cities, and countries of residence
- Phone numbers and Steam account email addresses
- Hardware purchase details, including the type and price of the items ordered
Valve assured customers that passwords, payment information, and Steam Guard codes were not exposed because Ceva does not have access to that sensitive data. However, the game publisher warned that attackers could exploit the stolen shipping details to mount convincing phishing campaigns. Affected buyers were advised to treat any unexpected emails, text messages, or phone calls mentioning their hardware orders as fraudulent, even if the messages correctly quote their home addresses to appear genuine.
Retailers and Other Major Brands Face Order Delays
Beyond the gaming sector, the data breach and subsequent warehouse disruptions have impacted several prominent European companies and institutions. Dutch online retail giant Bol reported that hackers gained access to two systems used to process orders at one of its fulfillment centers, leading to order delays and cancellations. Bol temporarily halted data exchanges with Ceva and took products stored at the affected Veerweg location offline.

Luxury retailer De Bijenkorf also warned customers of processing delays for orders, returns, and refunds. Local media and reports confirmed that additional organizations—including football club Ajax, banking giant ING, and eyewear maker Ace & Tate—had customer shipping details exposed in the attack.
Mark Schenkel, a spokesperson for the Dutch data protection authority, stated that the agency received data breach reports from 10 organizations in connection with the incident. Meanwhile, affected companies continue to press Ceva for the full scope of what was taken and how the intrusion occurred, as Ceva has not yet publicly disclosed how the attackers gained access or the exact number of individuals affected.