Hackers Got Your Home Address by Breaching the Shipping Company Behind Steam and ING
A hack at shipping giant CEVA Logistics exposed names, home addresses, and order details for customers of Steam, ING Bank, and major retailers across Europe.
You've Never Heard of CEVA Logistics. Hackers Have.
You placed an order. You paid. The package arrived. You moved on.
But behind that smooth experience, a company you never chose and probably never noticed handled the warehouse, the pick-and-pack, and the shipment tracking. That company is CEVA Logistics, one of the world's largest shipping operators. On July 29, 2026, attackers broke into its systems. At least eight European warehouses were hit.
The brands affected include names you know well: Valve (the company behind Steam), ING Bank, Dutch online retailer Bol, luxury department store De Bijenkorf, football club Ajax, and eyeglass brand Ace & Tate. CEVA confirmed the intrusion on August 1. Valve notified affected Steam hardware buyers on August 7.
The attackers never touched Steam. They never touched ING. They went around them both, straight to the invisible middleman.
How Does a Shipping Company End Up With Your Home Address?
When you buy physical goods online, the retailer outsources the heavy lifting. A company like CEVA receives inventory, stores it in a warehouse, packs your order, prints your label, and coordinates delivery. To do that job, CEVA needs your full name, home address, phone number, email address, and a record of exactly what you bought and what you paid.
That is a rich profile. It tells a criminal where you live, what you can afford, and what you own.
In this breach, attackers got all of it. Names, home addresses, phone numbers, email addresses, order contents, and purchase amounts were all compromised. Payment card details were not taken. Account passwords and Steam Guard codes were not taken either. That matters, but it does not make the exposure minor.
Your home address is not a password. You cannot change it.
Who Is Actually at Risk?
If you bought Steam hardware, a Steam Deck, a Steam Controller, any physical Valve product, you may have received an email from Valve around August 7. That notification means your data was in CEVA's systems.
If you ordered from Bol, De Bijenkorf, Ajax's merchandise store, Ace & Tate, or through ING Bank during a period when CEVA handled their logistics, the same applies to you, even if you never received a direct notification. Not every affected brand has been fully transparent about customer exposure.
This is the classic supply-chain attack. The term sounds technical. The concept is simple: rather than trying to breach a hardened target, attackers found a softer one in the same ecosystem. Every company that relied on CEVA for fulfillment shared its exposure, and so did every customer of those companies.
What Can Criminals Do With a Name and an Address?
Quite a lot. Home addresses enable physical mail fraud and package interception, but the real risk is more targeted. With your name, address, email, and a record of what you purchased, a criminal can craft a convincing follow-on attack. It will reference a real product you actually bought. It will arrive looking like a shipping update or a return confirmation. It will feel real because the attacker is working from real data.
This is not speculation. It is the standard playbook after a breach like this. Stolen data gets sold, resold, and eventually ends up in fraud kits that less sophisticated criminals use months or even years later.
What to Do Right Now
-
Check your inbox for breach notifications. Look for messages from Bol, De Bijenkorf, Ajax, Ace & Tate, ING, or Valve. Read them carefully. Do not dismiss them as spam.
-
Be suspicious of shipping emails for the next several months. Legitimate carriers do not ask you to click a link to reschedule delivery and re-enter your payment details. If a message references a real order and asks you to act urgently, go directly to the retailer's website instead of clicking anything.
-
Protect your email account first. Your email is the master key to every other account. Update the password and enable two-factor authentication. Use an authenticator app rather than SMS if you have the option.
-
Ask your bank about fraud monitoring. In the Netherlands and across the EU, banks and credit bureaus offer mechanisms to flag unusual account activity. A fraud alert costs nothing and stops many forms of identity-based fraud before it starts.
-
Look up data broker opt-outs. Your address is now in criminal hands. Data removal services and manual opt-out requests to brokers will not undo what happened, but they reduce how many other pathways lead to you.
-
Watch for physical mail fraud. Printed letters designed to look like official correspondence from banks or government agencies are a low-tech but effective follow-on to address leaks. Be skeptical of anything unexpected that asks you to call a number or visit a website.
The Part Nobody Wants to Say Out Loud
You did everything right. You bought from a reputable retailer. You used a strong password. You never clicked a phishing link. And your home address is now in a criminal database anyway.
That is the uncomfortable logic of supply-chain attacks. Your security is only as strong as the weakest vendor in a chain you never audited and never consented to join. Every company that ships a physical product outsources risk to a network of logistics providers, warehouse operators, and last-mile carriers. Most of those vendors hold your data. Almost none of them tell you they exist.
The next breach will follow the same pattern. Attackers are rational. They go where defenses are thinnest and data is richest. Shipping infrastructure sits at exactly that intersection for millions of transactions every day.
Do this now:
- Check your inbox for breach notifications from CEVA-linked brands
- Enable two-factor authentication on your email account
- Treat any urgent shipping-related email as suspicious for the next few months
- Contact your bank about fraud monitoring options
- Look into data broker opt-outs to reduce your exposure going forward
Sources
Common Questions About Breach
What should I do immediately after a data breach?
Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.
How long do companies have to notify me after a data breach?
In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.
Should I freeze my credit after a data breach?
Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.
More in breach
Stay invisible. Follow @hack_decoded