cyber-crime

Valve, Bol, ING, Ajax, and others affected as pwnage disrupts eight European warehouses

A cyberattack on logistics giant CEVA has disrupted warehouses across Europe and exposed customer data belonging to a growing list of big-name clients, including Valve and Ajax.The France-headquartered shipping outfit, which operates more than 1,000 warehouses worldwide and generated $18.3 billion in revenue last year, was attacked between July 29 and August 1, according to a notification Valve sent to customers.Eight CEVA warehouses in Europe were affected, industry news site FreightWaves reported, citing a source familiar with the investigation. The disruption hit parts of CEVA's contract logistics business, though its air, ocean, ground, and rail transportation operations continued as normal.

The fallout is now showing up at companies that rely on CEVA to get their wares into customers' hands.

Valve, which uses CEVA to ship Steam hardware in Europe, told customers in an email seen by The Register that attackers had likely stolen their information.The haul potentially includes names, street addresses, postcodes, countries, phone numbers and email addresses, along with the type and price of Steam hardware the punters ordered. CEVA retains the information for up to 90 days after an order, according to Valve, which is contacting customers it believes may have been affected.Payment information, passwords, and Steam Guard codes weren't exposed because CEVA doesn't have access to them, Valve said.The stolen data does, however, hand crooks plenty of material for convincing phishing attempts, Valve warned customers.