CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments

CEVA Logistics suffered a cyberattack disrupting European operations, with eight warehouses affected and shipments halted at impacted sites.

CEVA Logistics suffered a cyberattack on July 29 that disrupted parts of its European operations. The incident impacted impacted eight warehouses, and the company is still working to restore impacted services. CEVA Logistics operates in more than 170 countries and is part of the CMA CGM Group, one of the world’s largest shipping and logistics companies.

On August 1, CEVA notified affected customers that goods stored at the disrupted facilities could not be shipped, highlighting the attack’s direct impact on logistics and supply chain operations.

The company did not disclose technical details about the attack or the threat actor behind the incident. At this time, no ransomware group claimed the responsibility.

The Register reported that the attack exposed customer data linked to major clients, including Valve and Ajax. Valve said payment details, passwords and Steam Guard codes were not exposed because CEVA does not have access to them. However, the stolen customer data could still be used by cybercriminals to craft convincing phishing campaigns.

Valve warned users to be cautious of suspicious emails or messages that may exploit information obtained in the breach to impersonate trusted services and trick victims into revealing sensitive information.

Some affected organizations warned that personal information may have been exposed, in addition to the delays affecting order shipments.

Dutch premium department store chain De Bijenkorf , which was also impacted, reported that the securoty breach may have exposed names, addresses, email addresses, phone numbers, and online order details. No financial data was impacted.

“Based on the current information, the following data may be involved:

-Name and contact details, such as email address, address, and telephone number.

-Data regarding online orders, such as products, prices, discounts, delivery information, and a description of the payment method used.” reported the company.

“For business customers, the company name and VAT number may also be involved if these have been entered in My Account. In the case of severely outdated VAT numbers for freelancers and sole proprietorships, a VAT number may be composed of a citizen service number.”

In November, a hacker reportedly offered the company’s database for sale on a dark web marketplace, claiming it contains customer lists, shipping records, contracts, pricing information and banking details. Such data could enable fraud, impersonation and attacks against global supply chain operations.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, logistics)

Leave a Reply

Your email address will not be published. Required fields are marked *

Subscribe to our Newsletter