preloader

· · digital-security third-party-risk supply-chain gdpr data-breach compliance europe incident-response

One Shipping Company Got Breached and Steam, ING and a Football Club Are All Now Writing to Their Customers About It

Source: The Register

None of the brands now emailing their customers about a data breach were the company that got breached, which is exactly why this incident is worth every security team’s attention.

One logistics vendor, disruption at eight warehouses

CEVA Logistics, a subsidiary of the French CMA CGM Group that provides warehousing, fulfilment and shipping for a long list of European retailers, was hit by a cyberattack between July 29 and August 1 that disrupted operations at eight of its European warehouses. CEVA began notifying affected retail clients on August 1. Valve, whose Steam hardware, including Steam Deck and Steam Machine orders, ships through CEVA in Europe, says it learned of the incident on August 7 and started emailing affected customers on August 10.

Data exposed without a single one of these companies being breached directly

The stolen data includes names, addresses, phone numbers, email addresses, and the type and price of items ordered, the delivery information any shipping partner needs to function. Valve was explicit that CEVA never had access to Steam account credentials, Steam Guard codes, or payment information, and that exposure was limited to what CEVA holds for up to 90 days after an order ships. Valve is not the only brand in this position. Football club Ajax, banking group ING, and eyewear retailer Ace and Tate have also confirmed that customer shipping information handled through CEVA was affected, a genuinely unusual spread of victims for a single logistics breach, spanning gaming, sport, finance and retail.

The part that should concern every company with a fulfilment vendor

Under GDPR, a controller’s breach notification obligations do not stop at the edge of its own network. Every one of these companies is now sending its own notifications, running its own risk assessment, and answering its own customers’ questions, for data compromised inside infrastructure none of them operate or can directly remediate. That is the defining risk of shared logistics, fulfilment, and delivery vendors: the security posture a company is actually exposed to is the weakest link across every processor holding its customer data, not just the systems it controls directly.

What this should prompt in your own vendor list

If your organisation ships physical goods, or shares customer PII with any logistics, fulfilment, or delivery partner, this is the moment to ask two questions: how long does that vendor retain delivery data after an order completes, and what does your contract actually require of them if they are breached. A 90-day retention window sounds short until it is multiplied across every order placed in that period, and a processor agreement that does not specify notification timelines leaves a company finding out from press coverage instead of a formal disclosure.

If you need help auditing which vendors hold your customers’ data, tightening data processing agreements around retention and breach notification, or building an incident response plan that covers breaches you did not cause but are still accountable for under GDPR, contact Excello Digital. We help European businesses map and manage the risk sitting inside their vendor list before it becomes a notification they have to send.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!