Steam gamers got breached by a warehouse they'd never heard of
A cyberattack on logistics firm Ceva Logistics leaked data belonging to Valve, banks, and retailers who never chose Ceva at all. Vendor risk never got scored at intake.
Between July 29 and August 1, a cyberattack hit eight European warehouses run by Ceva Logistics, a contract logistics firm most consumers have never heard of. Names, addresses, phone numbers, emails, and order data leaked out. Payment details and credentials weren't touched, which is the only reason this isn't a bigger story than it already is.
Here's the part that should unsettle anyone who owns vendor decisions: the people whose data leaked weren't Ceva's customers. They were customers of Ceva's customers. Valve's Steam hardware buyers got notified. Dutch retailer Ajax's shoppers got notified. Banks got pulled in. Nobody who actually had their data exposed picked Ceva. Someone two or three contracts upstream did, for reasons that had nothing to do with the people now dealing with a breach notice.
That's not a Ceva problem. That's a scoring problem, and it's everywhere.
The vendor you never scored
Every org has a process — formal or not — for picking new vendors, partners, and logistics providers. It usually scores price, service level, capacity, maybe a reference call. What it almost never scores is blast radius: if this vendor gets breached, goes down, or gets acquired by someone worse, how far does the damage travel, and past how many parties who never consented to the exposure?
That question doesn't show up on a standard vendor scorecard because it isn't about the vendor's competence. Ceva is, by all accounts, a serious operator — the attack didn't spread past the eight affected warehouses, and the rest of its air, ocean, ground, and rail operations kept running normally. Containment worked. The exposure still happened, because the risk wasn't in how well Ceva runs its warehouses. It was in how many unrelated companies had quietly built dependencies on top of it without anyone scoring that concentration.
Intake solves this for projects. It rarely gets applied to vendors
This is the exact gap that weighted scoring exists to close — just pointed at the wrong door. Most teams that have gotten disciplined about intake apply it to inbound project requests: every request gets scored on value, effort, risk, before it gets resourced. Fewer teams apply the same rigor going the other direction, to the vendors and dependencies they're signing up to rely on.
A vendor relationship is a project. It has a cost, a benefit, and a risk profile — and that risk profile should include "how many downstream parties inherit exposure if this fails," not just "will this vendor deliver on time." Treat vendor selection like any other intake decision — a form, a scoring rubric, an owner who signs off — and blast radius becomes a criterion you weight, not an afterthought you discover in a breach notification email.
The Dutch Data Protection Authority is now investigating. Ceva will absorb the regulatory and reputational cost. But the actual failure sits further upstream, in every company that added Ceva — or any vendor — to their supply chain without ever running the dependency through a decision process that asked what happens when, not if, it fails.
The fix isn't more vendors, it's more scoring
Nobody's going to stop using third-party logistics, cloud providers, or payment processors. Concentration is the whole point of specialization. But "we chose a reliable vendor" and "we scored what happens if that vendor's reliability runs out" are two different exercises, and most organizations only do the first one.
If your organization runs intake and scoring for the work you take on, it's worth asking whether the same discipline applies to the dependencies you take on too — because right now, for a lot of companies, the answer is a vendor list nobody scored and a breach notice nobody expected.
Sources: A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond, TechCrunch, August 10, 2026; Cyberattack on logistics giant CEVA delivers customer data into the wrong hands, The Register, August 11, 2026; Ceva Logistics Operations Disrupted by Cyberattack, SecurityWeek.