Technology
Cyberattack on logistics giant CEVA delivers customer data into the wrong hands
Key Points
A cyberattack on logistics giant CEVA has disrupted warehouses across Europe and exposed customer data belonging to a growing list of big-name clients, including Valve and Ajax. The France-headquartered shipping outfit, which operates more than 1,000 warehouses worldwide and generated $18.3 billion in revenue last year, was attacked between July 29 and August 1, according to a notification Valve sent to customers. Eight CEVA warehouses in Europe were affected, industry news site FreightWaves...
A cyberattack on logistics giant CEVA has disrupted warehouses across Europe and exposed customer data belonging to a growing list of big-name clients, including Valve and Ajax. The France-headquartered shipping outfit, which operates more than 1,000 warehouses worldwide and generated $18.3 billion in revenue last year, was attacked between July 29 and August 1, according to a notification Valve sent to customers. Eight CEVA warehouses in Europe were affected, industry news site FreightWaves reported, citing a source familiar with the investigation. The disruption hit parts of CEVA's contract logistics business, though its air, ocean, ground, and rail transportation operations continued as normal. The fallout is now showing up at companies that rely on CEVA to get their wares into customers' hands. Valve, which uses CEVA to ship Steam hardware in Europe, told customers in an email seen by The Register that attackers had likely stolen their information. The haul potentially includes names, street addresses, postcodes, countries, phone numbers and email addresses, along with the type and price of Steam hardware the punters ordered. CEVA retains the information for up to 90 days after an order, according to Valve, which is contacting customers it believes may have been affected. Payment information, passwords, and Steam Guard codes weren't exposed because CEVA doesn't have access to them, Valve said. The stolen data does, however, hand crooks plenty of material for convincing phishing attempts, Valve warned customers. "Expect fake messages – email, SMS or phone – that mention your hardware order and appear to come from Steam, Valve or a delivery company," Valve said. "They may quote your address back to you to prove they're genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to 'verify' your order. Treat all of them as fake." Dutch e-commerce giant Bol is also dealing with the fallout. It said the incident involved two systems used to process orders at one of its fulfillment centers and warned that customer information may have been viewed or copied. The retailer halted data exchanges with CEVA and temporarily took products stored at the affected Veerweg location offline. Some orders were canceled or delayed, and as of August 6, operations at the facility had yet to be fully restored. Dutch department store De Bijenkorf has similarly warned customers about compromised data and disruption to orders and returns. Local media reports say football club Ajax, banking giant ING, and eyewear maker Ace & Tate also had customer shipping details exposed in the incident. CEVA has yet to disclose publicly how the attackers got in, how much data they stole, or how many companies and individuals were affected. The company did not respond to The Register's questions. For a company whose business is keeping track of other people's packages, CEVA is still leaving rather a lot unaccounted for. ®