Ceva Logistics discloses data breach affecting Steam, banks
A cyberattack on Ceva Logistics exposed personal data of customers from banks, retailers, and Steam gamers, raising fraud risks. The breach highlights vulnerabilities in global supply chain logisticsโฆ
A cyberattack on Ceva Logistics, a global shipping giant handling millions of packages daily, has exposed personal data belonging to customers of banks, retailers, and even Steam gamers. The breach, revealed in recent disclosures, affected companies that rely on Ceva for supply chain logistics, raising concerns about the security of customer information tied to shipments. Investigators say hackers gained access to Cevaโs systems earlier this month, though the full scope of the breach and the exact timeline remain unclear.
Ceva Logistics, which operates in over 170 countries and manages freight for major brands, has become a prime target due to its central role in global trade. The attack follows a pattern of ransomware groups targeting logistics firms, which often hold troves of customer dataโincluding names, addresses, and payment detailsโcollected during order fulfillment. Experts warn that such breaches can have cascading effects, as compromised data may be reused in phishing scams or sold on dark web marketplaces, putting consumers at risk of fraud.
The fallout is already spreading. Financial institutions like banks and fintech companies are notifying affected customers after discovering their data was stored in Cevaโs systems. Major retailers, including those selling electronics and apparel, have also reported potential exposure, while Steam usersโwho ship physical goods tied to gaming accountsโare scrambling to secure their information. Ceva has not confirmed the number of affected records, but cybersecurity researchers tracking the incident estimate it could run into the hundreds of thousands.
What happens next depends on Cevaโs response. The company is reportedly working with law enforcement and cybersecurity firms to contain the breach, but the delay in public disclosure has drawn criticism from privacy advocates. Regulators in the U.S. and Europe may launch investigations under laws like GDPR or CCPA, which require timely breach notifications. For consumers, the incident underscores the risks of relying on third-party logistics providersโand the need to monitor accounts for unusual activity. If history is any guide, this wonโt be the last supply-chain attack of its kind.
Read Full Story at TechCrunch โ


