Connect with us

Infosecurity

Ceva Logistics Data Breach: What European Clients Need to Know

Published

on

Ceva Logistics data breach

What Happened at Ceva Logistics?

One of the world’s largest logistics companies has been hit by a data breach that’s sending ripples through its European client base. Ceva Logistics, a subsidiary of the French shipping giant CMA CGM Group, confirmed that its contract logistics operations in Europe were targeted.

The company, which handles warehousing, fulfilment, and aftermarket services for a range of big-name clients, said it notified affected customers on August 1. In a statement seen by Infosecurity, Ceva revealed that eight warehouses were impacted. The firm was quick to add that “no other Ceva systems globally were affected, and all other operations continue without incident.”

But the silence around the specifics has left many customers guessing about the scale of the exposure.

Valve and Steam Customers Caught in the Crossfire

One of the most high-profile casualties is Valve, the video game developer behind the Steam platform. In an email to its customers, Valve explained that the cyber-attack ran from July 29 to August 1. During that window, attackers may have accessed delivery-related information that Ceva holds for Steam’s physical hardware shipments in Europe.

“Ceva receives specific delivery-related information from Steam to be able to ship physical hardware to customers in Europe, and told us these are the details the attacker likely took,” Valve wrote. “Because Ceva retains this information for up to 90 days after that order, we are sending this message to all customers we can assume were impacted.”

The data potentially exposed includes names, email and home addresses, phone numbers, and order details. That’s a goldmine for cybercriminals, even if it doesn’t include financial information.

Who Else Is Affected?

Valve isn’t alone. Dutch online retailer Bol has publicly acknowledged the disruption, saying that restoration of operations at Ceva’s Veerweg location is taking longer than expected and could affect service levels. Other impacted clients include department store chain De Bijenkorf, football club Ajax, and banking giant ING.

The breadth of the victim list shows just how interconnected the logistics sector is. A single breach at a third-party provider can cascade through dozens of companies and thousands of consumers.

Why Logistics Companies Are Prime Targets

Joseph Perry, cybersecurity researcher and advanced services lead at Arcova, argues that logistics firms are an obvious choice for cybercriminals. “They sit at the center of thousands of transactions between businesses and their customers,” he said. “That makes them an appealing target because a compromise can create operational problems while also giving attackers access to information about the people and products moving through the system.”

Perry also stressed that shipping data is highly contextual. “A name, address, phone number, email address, and recent purchase can give attackers enough context to make phishing and impersonation attempts far more convincing.”

His advice? Treat logistics companies as “part of the security and operational environment” of everything that depends on them. “You do not have to be the final target to become the point of failure,” he added.

The Phishing Wave You Should Expect

Anna Collard, CISO advisor at KnowBe4, described the incident as a “textbook supply chain breach.” And she’s already predicting the fallout.

“I’d expect a wave of ‘delivery problem’ lures over the coming weeks, messages about a redelivery fee or a request to ‘verify’ an order,” Collard warned. “So treat any unexpected message about this order as fake, don’t click links or pay fees, and go directly to the retailer’s official site by typing the address yourself.”

That’s practical advice. If you’ve recently ordered physical hardware from Steam or made a purchase from Bol or De Bijenkorf, be extra cautious about any unsolicited messages referencing a delivery. Real companies rarely ask for payment via text or email.

A History of Attacks on CMA CGM

This isn’t the first time CMA CGM has faced a cybersecurity crisis. In 2020, the shipping giant suffered a ransomware attack on its servers, forcing the temporary closure of its shipping website and applications. That incident disrupted operations for days and highlighted the vulnerability of the maritime logistics sector.

The recurrence raises questions about whether enough has been done to harden the group’s defenses since then. While Ceva insists the latest breach is contained, the fact that customer data was stolen suggests gaps remain.

For businesses that rely on logistics partners, the lesson is clear: you’re only as secure as your weakest link. Regular security assessments of third-party vendors aren’t optional anymore. They’re essential. And for consumers, the takeaway is simpler: verify before you click.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

De Bijenkorf warns of possible customer data exposure after logistics partner cyberattack

Published

on

De Bijenkorf cyber incident

What happened at De Bijenkorf?

Dutch luxury department store chain De Bijenkorf has warned that customer data may have been exposed after a cyberattack hit one of its logistics providers. The incident, disclosed Wednesday, has thrown a wrench into the retailer’s operations — deliveries are dragging, returns are stuck, and refunds are moving at a snail’s pace.

The Amsterdam-based company was quick to clarify that its own systems were not breached. The attack targeted only the infrastructure of an external logistics partner. “Our logistics partner intervened immediately, blocked access, and took additional security measures,” De Bijenkorf said in a statement. Stores, the website, and the mobile app remain fully operational.

Still, the fallout is real. Customers can place online orders, but they shouldn’t expect speedy delivery. The company is also processing returns and refunds slower than usual while the investigation grinds on.

What customer data could be exposed?

The investigation is still in its early stages, and De Bijenkorf hasn’t confirmed whether any data was actually accessed — or how many people might be affected. But the potential scope is unsettling.

The logistics provider may have held names, email addresses, postal addresses, phone numbers, and details tied to online purchases. That includes ordered products, prices, discounts, delivery information, and the payment method used. For business customers, company names and VAT numbers could also be in the mix.

Here’s the silver lining: no payment card details, bank account numbers, usernames, or passwords were stored by the logistics partner. So those sensitive pieces of data are likely safe. Customer accounts are also not believed to be at risk, since no login credentials were involved.

De Bijenkorf has already notified potentially affected customers as a precaution and reported the incident to the Dutch data protection authority. The company hasn’t said whether ransomware was involved or if a ransom demand was made. No threat actor has publicly claimed responsibility.

A growing pattern: attackers go after the weak link

This isn’t an isolated event. Cybercriminals are increasingly targeting retail giants indirectly — by compromising their suppliers and service providers instead of going head-to-head with hardened corporate defenses.

Earlier this week, Polish convenience store behemoth Żabka disclosed unauthorized access to its internal systems after attackers allegedly compromised an account belonging to an external service provider. The company said customer-facing services and payment systems were unaffected.

In July, discount supermarket operator Lidl reported that customer information from its online stores in Germany, Belgium, and the Netherlands was exposed after attackers breached one of its IT service providers.

The pattern is clear. Attackers find the soft underbelly — a third-party vendor with weaker security — and use it as a gateway to reach the bigger prize.

Logistics attacks ripple through the supply chain

The damage isn’t always limited to data. In July, a ransomware attack on Japan’s largest refrigerated logistics company disrupted food deliveries nationwide. Restaurant chains, including Kentucky Fried Chicken, faced supply shortages. It was a stark reminder of how an attack on a single logistics provider can send shockwaves through the entire retail supply chain.

The luxury sector has also felt the heat. Both Harrods and Louis Vuitton reported cybersecurity incidents in 2025. These are brands with massive security budgets — yet they still got hit, often through third parties.

What should De Bijenkorf customers do now?

If you’re a De Bijenkorf customer, here are a few practical steps to consider while the investigation unfolds:

  • Watch your inbox for official notifications from the retailer — they’ll tell you if your data was likely affected.
  • Be extra cautious with unsolicited emails or calls claiming to be from De Bijenkorf. Phishing attempts often spike after breaches like this.
  • Monitor your bank statements and online accounts for any unusual activity, even though payment details weren’t stored by the logistics provider.
  • If you’re a business customer, keep an eye on your VAT records and company information.

De Bijenkorf operates seven department stores in the Netherlands and employs roughly 4,500 people. The company has promised to keep customers updated as the investigation progresses.

This incident is another reminder that in today’s interconnected retail ecosystem, your security is only as strong as your weakest vendor. For more on how third-party risks are shaping the threat landscape, check out our coverage of supply chain cyberattacks in retail and how logistics providers become prime targets for ransomware gangs.

Continue Reading

Infosecurity

One Phone Call, Two Malware Strains: How WindRelay and SpyNote Turned a 13-Minute Call Into a Loan Fraud

Published

on

WindRelay NFC malware

A 13-Minute Call That Cost a Victim Their Identity

It took just 13 minutes. One phone call, a fake bank employee on the line, and a victim who followed instructions to install a single app. By the time the call ended, a fraudster had taken out a loan in the victim’s name and relayed their card data to a fake terminal — all while keeping them engaged in conversation.

Security firm Group-IB documented the case in a technical write-up published on August 12. The researchers tracked the NFC malware as WindRelay and attributed the remote access trojan (RAT) to a variant of SpyNote. The scam is a stark reminder that NFC relay fraud is no longer just a theoretical risk — it’s a live, operational threat.

The fraudster called posing as a bank employee, claiming there was a problem with the victim’s card. Then came the pitch: install this app to fix it. The victim complied, and the nightmare began.

An App Named After Its Victim

The RAT arrived through the device’s package installer — the standard route for sideloading outside an app store. But here’s the twist: its app label carried the victim’s own name, not a generic or impersonated brand.

SpyNote ships with a builder toolkit that lets an operator set a custom app name, label, and package name. So personalization isn’t manual effort — it’s built into the tool. Group-IB said the label pointed to pre-call reconnaissance that harvested the victim’s name and phone number. That meant there was no unfamiliar app name to give the victim pause.

With the RAT active, the fraudster used its remote access to install WindRelay himself. No further action was required from the victim. Notably, no screen sharing was triggered at any point — a detail that matters for detection.

One Tap, Two Payouts

WindRelay’s permissions mapped its purpose with chilling clarity:

  • NFC — to read the card
  • INTERNET — to stream captures out live
  • READ_CONTACTS — to reach further targets
  • DUMP — unusual in a third-party app, used to inspect device state

When the victim tapped their card as instructed, the malware acted as a contactless reader. It captured the live exchange between chip and reader, including the one-time code generated for that transaction. That exchange was streamed to a second device held by the fraudster, which presented itself as the card to a real terminal.

But the fraudster didn’t stop there. Using the same remote access, they took out a loan through the victim’s banking app. Group-IB read this as an opportunistic add-on rather than a planned step — a quick grab while the iron was hot. Card transactions began appearing shortly after the call ended.

23 Samples, Three Countries

Group-IB linked WindRelay to 23 samples uploaded to VirusTotal between November 2025 and July 2026. The malware impersonated institutions in Czechia, Slovakia, and Slovenia — a targeted, regional campaign rather than a scattergun operation.

This isn’t an isolated incident. Ghost Tap malware has fueled a surge in remote NFC payment fraud, and this case shows the tactics are evolving. The combination of a RAT and NFC relay in a single call is a new level of sophistication.

How to Spot and Stop This Scam

Group-IB’s recommendations are practical and worth heeding:

  • Don’t treat screen-sharing detection as a proxy for remote access — this attack never used it.
  • Alert on app installations from non-official sources during an active call.
  • Flag loan disbursements that coincide with physical card transactions.

For individuals, the advice is simpler: never install an app at the direction of an unsolicited caller. Banks don’t work that way. If someone on the line claims to be from your bank and asks you to install anything, hang up and call the number on your card.

The 13-minute call is over, but the impact could last years. As NFC payment fraud grows, understanding the mechanics of attacks like this one is the first line of defense.

Continue Reading

Infosecurity

Russian Businesses Scrub Durov-Linked Products After ‘Terrorist’ Designation

Published

on

Durov terrorist designation

Moscow’s Market Turns on Durov

Just days after Russia’s Federal Security Service (FSB) charged Pavel Durov with aiding terrorist activity, a quiet purge is underway. Russian businesses are pulling products linked to the Telegram founder from shelves and websites. The move follows a formal ‘terrorist’ designation announced last week.

The FSB didn’t stop at charges. It says it will seek to place Durov on an international wanted list. The agency accuses Telegram of failing to remove channels and bots allegedly used by Ukrainian intelligence, as well as terrorist and extremist groups.

Now, the commercial fallout is hitting home. From retail chains to online services, companies are distancing themselves from anything bearing Durov’s name or brand.

What Products Are Being Removed?

Early reports point to a range of items. Some retailers have pulled branded merchandise, while others have scrubbed digital services tied to Durov’s ventures. The exact list is still emerging, but the trend is unmistakable: erasing Durov from the Russian market.

One notable example involves a popular messaging app feature. Businesses that once promoted Durov’s Telegram encryption features are now quietly deleting those references. It’s a stark reversal for a figure once celebrated as a tech visionary.

The FSB’s Case Against Durov

The charges stem from Telegram’s moderation policies. Russian authorities claim the platform harbors channels used by Ukrainian intelligence to coordinate operations. They also point to extremist content that allegedly flourishes without removal.

Durov, who left Russia years ago, has consistently denied wrongdoing. His supporters argue the charges are politically motivated. Yet the FSB’s designation carries real weight, and businesses are responding accordingly.

This isn’t just about legal risk. It’s about optics. In today’s climate, being linked to a ‘terrorist’ is a death knell for commercial partnerships.

Market Reaction and Public Sentiment

The business community is moving fast. Some firms issued terse statements confirming the removal. Others have stayed silent, hoping to avoid attention.

Public opinion is split. Some Russians view Durov as a hero who stood up to state pressure. Others see him as a liability. The designation has intensified that divide, with pro-Kremlin voices applauding the move.

For now, the practical impact is clear: Durov’s brand is toxic in Russia. Companies that once leveraged his name for credibility are now scrambling to cut ties.

What Happens Next?

Legal experts say the international wanted list request could complicate Durov’s travels. He currently resides outside Russia, but extradition risks loom if he visits allied countries.

Telegram itself remains operational, but the pressure is mounting. The FSB’s accusations could lead to broader restrictions on the platform within Russia, affecting millions of users.

For businesses, the calculus is simple. Stay away from Durov, or face the consequences. The purge is likely to expand as authorities tighten the screws.

Why This Matters Beyond Russia

This isn’t just a Russian story. Telegram is a global platform with hundreds of millions of users. The FSB’s actions could set a precedent for other governments targeting tech founders.

It also raises questions about free speech and moderation. If a state can label a tech leader a terrorist for content policies, what stops others from doing the same? The implications are chilling for the industry.

As Telegram’s legal battles unfold, the world is watching. Durov’s fate may well shape how platforms handle sensitive content for years to come.

For now, Russian businesses are voting with their feet. The message is clear: Durov is out, and they want nothing to do with him.

Continue Reading

Trending