● EN VIVO

EL DIARIODICE

Independent digital journalism, economy and analysis

← Back to homepage
Technology⏱️ 2 min read

Massive data leak: the breach hitting Steam, ING and millions of customers

Massive data leak: the breach hitting Steam, ING and millions of customersPhoto: TechCrunch

A cyberattack on Ceva Logistics, one of the world’s largest freight carriers, triggered a data leak that spills over to giants such as Valve (Steam’s owner), bank ING and several European retail chains. Names, addresses and order details were exposed.

What happened

The attack, detected in late July, disrupted the French company’s operations at at least eight European warehouses and compromised shipping databases: customer names, home addresses, phone numbers, emails and the details of orders placed.

The scale became clear in the following days, when Valve alerted Steam hardware buyers — including Steam Deck owners — that their shipping data was among the exposed, and companies such as Dutch online retailer Bol, luxury retailer De Bijenkorf, football club Ajax and bank ING began notifying customers.

Why this breach matters

The case is a textbook example of a supply chain attack: the attackers didn’t hack each company directly, but the logistics middleman they all share. That concentration multiplies the damage of a single breach.

The Dutch data protection authority confirmed that at least ten organizations reported incidents linked to the same attack, making this one of the most far-reaching incidents of the year in Europe.

What data was exposed

According to security analysts, the leaked information includes basic personal data (name, address, phone, email) and order details, but so far no passwords or banking data have been reported in the breach.

That doesn’t make it harmless: with real names and addresses, criminals can run extremely credible phishing campaigns — messages posing as the parcel company, the bank or Steam — to steal credentials or financial information.

How to protect yourself if you shopped online

Experts recommend that anyone notified by any of the affected companies take three steps: change the passwords of related accounts, enable two-factor authentication, and distrust any message asking for personal or payment data.

If you receive an email from “your courier” with a link to track your shipment, don’t open it from the message: go directly to the company’s official site. Scammers exploit the urgency of the moment so the click is automatic.

The key figure

10 organizations. That is how many companies confirmed being hit by a single breach in the logistics chain. When the weak link is the one everyone shares, everyone falls.

Sources

  1. techcrunch.com
  2. infosecurity-magazine.com
  3. itpro.com
  4. helpnetsecurity.com