decrypted · 10 august 2026 · supply chain · uk policy and law · ai and llm security

The Ceva Logistics breach that hit Steam, ING and Ajax, and the data it didn't need to keep

Today's biggest story is not really about the company whose name is on the box. It is about the company that delivers the box. Ceva Logistics, the French freight operator that handles last-mile delivery for retailers across Europe, has confirmed a cyberattack between 29 July and 1 August that has since surfaced in breach notices from Valve's Steam hardware business, Dutch retailers Bol and De Bijenkorf, eyewear chain Ace & Tate, banking group ING and football club Ajax. None of those organisations were themselves hacked. Their customers' delivery details were, because Ceva was holding onto them long after the parcel had arrived.

What happened

Ceva says the intrusion hit eight of its European warehouses and disrupted operations before it isolated the affected systems. It has not said how attackers got in or whether a ransom was demanded. What is clear is the scope: Valve, whose Steam Deck, Steam Machine and Steam Controller hardware ships through Ceva to European buyers, told customers this week that names, addresses, phone numbers, order details and the email addresses linked to their Steam accounts had likely been exposed. No passwords, payment details or Steam Guard codes were taken, because Ceva never had access to them in the first place. The reason customers who ordered months ago are affected at all is that Ceva keeps delivery records for up to ninety days after an order, well beyond the point where a courier still needs them to get a parcel to a door.

The lesson: data you no longer need is data you can lose

The mechanism here is simple enough to explain without jargon. Think of a delivery firm's systems as a filing cabinet at the depot. Once your parcel has arrived, there is no operational reason to keep a copy of the label, your phone number and what you bought sitting in that cabinet for three months. But it was there, and when the depot was broken into, the copies were just as useful to the thief as anything else in the building, even though the depot never touched your bank card.

This is the Secure by Design failure mode that matters here, and it is not really Ceva's alone. Any UK retailer, bank or club that ships physical goods hands customer data to a logistics partner, and that partner's data retention policy becomes part of your own attack surface whether it appears in your risk register or not. Two things follow. First, retention limits are a control, not paperwork: data deleted the moment it stops being operationally necessary cannot be stolen later. Second, UK data protection law does not care whose server the data sat on. If a sub-processor's negligence exposes a UK customer's details, the controller who chose that sub-processor still has to explain the choice, the contract and the retention terms to the ICO. Valve says it is notifying data protection authorities in the countries affected; UK organisations using the same category of logistics or fulfilment vendor should be asking now, not after a similar notice arrives, how long those vendors keep delivery data and why.

Also this week

An AI agent went hunting for vulnerabilities on its own, and found three. CISA has flagged active exploitation of flaws in Langflow, Apache Tomcat and N-able N-central, but the detail worth noting is how the Tomcat flaw (CVE-2026-34486, a bypass of its cluster encryption) was found and used: Palo Alto Networks attributes a campaign against more than 460 targets to an autonomous system running on DeepSeek via the Hermes Agent framework, which switched to alternative vulnerabilities on its own when its first attempt failed. UK organisations running internet-facing Tomcat clusters should treat "nobody is actively targeting us" as a weaker assumption than it used to be.

Britain's energy regulator has decided cyber baselines are not optional. On 5 August, DESNZ and Ofgem published their response to a consultation on cyber resilience across downstream gas and electricity, confirming that all Ofgem licensees will need to meet a Cyber Essentials Plus baseline, extended to cover operational technology, governance and supply chain management, with full rollout targeted for 2030. It will not move fast enough to help anyone this year, but it puts supply chain accountability, the same theme running through the Ceva story, into energy sector regulation for the first time.

Sources

If this raises questions about data retention risk in your own supply chain, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.