Brands
Latest top stories
Technology

One hack, a chain of damage

17 August 2026

 

A customer waiting for a parcel from Bol, De Bijenkorf or Valve would have had little reason to think about CEVA Logistics. The company sat several steps behind the purchase, storing products, processing orders and moving goods through European warehouses.

Then CEVA suffered a cyberattack.

The incident, which began on 29 July, affected eight European warehouses. Orders were delayed and companies that used CEVA’s logistics services began warning customers that their personal information might have been exposed.

Valve said the potentially compromised data included names, addresses, telephone numbers, email addresses and details of hardware purchases. Payment information, passwords and Steam Guard authentication codes were not held by the logistics provider. Even so, the stolen information offered criminals useful raw material: enough to send a plausible message about a Steam Deck delivery, a customs charge or a failed payment.

CEVA had not publicly explained how the attackers entered its systems at the time of writing. The company said its investigation was continuing.

The breach captures several features of modern cyber risk in a single incident. The organisation that is attacked may not be the name familiar to consumers. Stolen data and physical disruption increasingly arrive together. And when the first notifications appear, even the affected companies may not yet know exactly what happened inside the supplier they trusted.

 

One breach, many front doors

 

Companies have spent decades outsourcing the machinery behind everyday business. Customer records sit in cloud platforms. Payroll passes through specialist providers. Retailers rely on external warehouses, payment processors and customer-service software.

This makes businesses more efficient, but it also creates concentration. Attackers no longer need to break into every retailer separately if one logistics or software provider holds information on behalf of many of them.

The CEVA attack turned a compromise inside a logistics company into delayed deliveries and data warnings carrying the names of several unrelated brands. Dutch shoppers may have thought they were dealing solely with Bol or De Bijenkorf; European gamers thought they had bought hardware from Valve. Their information had travelled farther down the supply chain.

A similar multiplier effect is visible in US data collected by the Identity Theft Resource Center (ITRC). Just 38 initial supply-chain compromises in the first half of 2026 ultimately affected 206 organisations and generated 280.6 million breach notices.

Those figures are American, but the business architecture they expose is international. A single breach can now move through a network of clients, customers and contractors before its full extent is understood.

 

The bill keeps climbing

 

IBM estimates that the global average cost of a data breach reached a record $4.99 million in 2026, 12% higher than a year earlier. Its study covered 602 organisations across 17 industries that experienced breaches between March 2025 and February 2026.

The largest costs do not necessarily come from replacing damaged equipment. They emerge as the incident spreads through the organisation: investigators must find the intrusion, systems remain unavailable, lawyers and regulators become involved, customers are notified and business is lost.

In a case such as CEVA, the disruption does not stop at the company boundary. Warehouses cannot ship goods, retailers must handle complaints, communications teams prepare warnings and customers become more vulnerable to follow-up fraud.

IBM’s figure is a benchmark rather than an average of every breach worldwide. The report was conducted by the Ponemon Institute and sponsored, analysed and published by IBM, which sells cybersecurity and AI-governance products. Even with those caveats, the direction is unmistakable: breaches are becoming operational business crises rather than isolated IT events.

 

AI accelerates an old criminal playbook

 

Artificial intelligence is adding speed to this system.

According to IBM, one in four malicious breaches in its 2026 study was AI-enabled, a 56% increase from the previous year. These incidents cost organisations an average of approximately $6 million—around $1 million more than the global breach average.

The methods are often familiar. Criminals still use phishing, malware, impersonation and stolen credentials. AI allows them to write convincing messages in several languages, imitate voices, personalise approaches and modify malicious code more quickly.

A logistics breach demonstrates the value of that combination. An attacker armed with a customer’s name, address, telephone number and recent purchase does not need to invent a vague phishing story. A message about a delayed parcel or additional delivery fee already fits the recipient’s circumstances.

At Black Hat USA 2026, the other side of this acceleration was equally visible. As MTN reported in Cybersecurity hands AI the controls at Black Hat USA 2026, security companies are giving AI systems greater authority to reconstruct attacks, prioritise threats and initiate responses.

Attackers and defenders are automating simultaneously. The advantage may belong to whoever notices and acts first.

 

The AI systems are targets too

 

Companies are not only using AI to defend existing infrastructure. They are connecting AI applications and agents to internal documents, customer records, databases and communications tools.

That creates another route into the business.

More than 20% of organisations in IBM’s study reported a breach targeting an AI model or application. The techniques included prompt injection, in which crafted instructions manipulate an AI system, and model inversion, which attempts to infer information about its training data. IBM put the average cost of a model-inversion breach at $6 million.

The risk increases when an AI agent can retrieve files, query databases or alter business systems. If its permissions are too broad, compromising the agent could give an attacker access to far more than a single application.

Security therefore has to follow the agent: limited permissions, traceable human authorisation and a record of every system and dataset it accessed.

 

Notifications without explanations

 

Europe has comparatively strong notification rules. Under the General Data Protection Regulation, organisations must generally notify the relevant supervisory authority within 72 hours when a personal-data breach is likely to pose a risk to people’s rights and freedoms. Individuals must also be informed when that risk is high.

Yet notification does not necessarily produce clarity.

A company may tell customers which information was exposed while revealing little about the original intrusion. Sometimes investigators genuinely do not know. In other cases, legal caution, commercial sensitivity or an active criminal investigation limits what is said publicly.

The scale of this transparency problem is clearest in the United States. The ITRC counted 471.2 million breach notices in the first half of 2026, already exceeding the 297.5 million issued throughout 2025. These notices do not represent 471.2 million unique people: one enormous incident involving the Canvas education platform accounted for an estimated 275 million.

More revealingly, only 24% of notices identified the attack vector. Before 2020, the ITRC says, almost all did.

Customers are increasingly told that something happened, but not whether it began with phishing, stolen credentials, an unpatched vulnerability, an insider or a compromised supplier. Other companies are denied information that could help them close the same route into their own systems.

AI may help narrow that gap. IBM found that organisations making extensive use of AI and automation in security operations recorded breach costs $1.93 million lower than those using none. That is an association, not a promise: well-automated companies may also have better-trained teams, larger budgets and stronger recovery plans.

Technology can shorten the time between intrusion and response. It cannot compensate for unknown suppliers, excessive access rights or an organisation that has never rehearsed what happens when a critical partner goes offline.

The CEVA incident did not remain inside CEVA. It travelled through warehouses, retail systems, customer inboxes and delivery schedules. That is increasingly what a data breach looks like: less like a locked door being forced open and more like a fault running through an entire commercial network.

The costs are rising because the connections are multiplying. Explaining where the failure began is becoming harder—and more necessary.

 

 

 

Liked this article? You can support our independent journalism via our page on Buy Me a Coffee. It helps keep MoveTheNeedle.news focused on depth, not clicks.

👉 https://buymeacoffee.com/movetheneedle.news