Your 3PL Just Got Hacked

Delivery truck at a dimly lit warehouse loading dock surrounded by packages
When a 3PL goes dark, the goods stop moving.

In early August, Valve told European customers who had bought its Steam hardware that their names, home addresses, phone numbers and email addresses had been stolen. Dutch online retail giant Bol had already warned its shoppers the same thing, and so had luxury department store De Bijenkorf, football club Ajax, bank ING and eyewear maker Ace & Tate. None of those companies was hacked. Their logistics provider was.

Ceva Logistics, one of the world’s largest freight and contract logistics operators and the logistics arm of shipping line CMA CGM, was hit by a cyberattack that began around July 29 and disrupted at least eight European warehouses. The intrusion froze shipments, delayed orders and spilled customer delivery data across a dozen brands in a single stroke. When you outsource your logistics, you outsource your security. A breach at your 3PL is your breach, paid for with your customers’ trust.

Ceva is not a small target. The company generated $18.3 billion in revenue in 2025, operates more than a thousand warehouses worldwide, and runs eight e-commerce fulfillment locations in the Netherlands alone, handling store replenishment and online orders for brands such as Bol, De Bijenkorf and Zalando. Its facilities hold stock for some of Europe’s most recognizable consumer names. The attackers knew exactly what they were hitting.

The attack began in the last days of July. Ceva confirmed to customers on August 1 that a cyber intrusion was affecting part of its European contract logistics operations. The consequences were immediate and physical. Goods sitting in affected warehouses stopped moving, shipments were delayed, and some orders were canceled outright. Bol suspended all data exchanges with Ceva as a precaution and said they would resume only when it was safe. Products at affected locations were taken offline until further notice.

Warehouse aisle with a glowing padlock hologram floating above parcels
One breach at a shared provider becomes a disclosure event for every customer.

Then came the disclosure wave. The compromised systems contained customer and shipment information belonging to multiple Ceva clients: names, postal addresses, postal codes, telephone numbers, email addresses, order numbers, tracking details, purchase histories, even messages attached to gift cards. Employee records were taken as well, and a former Ceva employee has filed a class action lawsuit over the theft, saying at least 100 employees have been harmed and that the affected number could extend into the thousands.

One detail from Valve’s notification should worry every supply chain executive. Ceva, Valve said, retains shipping and delivery data for 90 days after an order. That means a customer who bought a Steam Deck in May was still sitting on Ceva’s servers in late July, ready to be copied. Data retention is not a storage decision. It is a risk decision.

The impact lands on people. The former employee behind the lawsuit describes fraudulent credit card charges and a surge of spam and scam phone calls after the theft. Consumers now face the quieter, slower damage of exposed delivery data: phishing messages that name them, cite their street address and reference a purchase they really made. That context is exactly what makes a scam believable.

Watch how the breach became a crisis. Eight warehouses, one intrusion, and within days a dozen separate companies writing their own customer notifications, freezing their own data links and hiring their own lawyers. Retailers, a bank, a football club and a gaming platform share little commercially, but they shared one warehouse operator. That is the structure of third party concentration risk. The brands were not breached, yet every one of them inherited a disclosure obligation, an operational disruption and a reputational cost.

Aerial night view of a large distribution center with cargo trucks at loading docks
Eight warehouses offline turned one intrusion into continent-wide delays.

Logistics providers have become prime targets for a simple reason: they sit at the intersection of rich customer data and physical goods. Cybercriminals who break into a freight company can steal personal information and, in the worst cases, coordinate the real world theft of trucks and containers. A 3PL breach is rarely only a data breach. The full scope of the Ceva incident is still unknown. The company has not said who was behind the attack or whether a ransom was demanded, and the investigation continues. Every affected brand should assume the list will grow.

So what do you do about a risk you cannot fully control? Start by asking your logistics providers three questions. First, which of their systems hold your customer data, and how long do they keep it after an order ships? Second, what is their notification commitment: will you hear from them within hours of an intrusion, or will you learn about it from your own customers? Third, if their warehouses go dark tomorrow, which of your orders are trapped inside, and how do you keep serving customers without them? Then run the scenario as a tabletop exercise with your own team. The first time you think through a 3PL outage should not be during one.

You cannot guarantee that your 3PL will never be hacked. But you can decide that you will never learn about it from a customer email, and that your data will not be sitting in someone else’s warehouse for 90 days after it should have been deleted. The next breach is not a question of if. It is a question of whose.