Investigation

Your home address was stolen from a company you have never heard of. It was doing exactly the job it was hired to do.

Two logistics breaches in one week exposed the quiet architecture of the data economy: the personal records of a dozen unrelated retailers' customers, pooled inside contractors no shopper ever chose, kept long past the day the package arrived.

A CMA CGM container ship in port. CEVA Logistics is a CMA CGM subsidiary.

Image: Quintin Soloviev / Wikimedia Commons (CC BY 4.0)

When customers of the video-game store Steam learned this month that their names and home addresses had been stolen, the notice did not come from Steam. It came by way of a company most of them had never heard of: CEVA Logistics, a contract-logistics firm that handles warehousing and shipping for retailers across Europe. Steam's operator, Valve, added one detail that is easy to skim past and worth stopping on. CEVA, it said, stores shipping and delivery information for ninety days after a purchase. So the address a shopper typed in to receive a graphics card in, say, May was still sitting in a warehouse contractor's system in late July, when someone broke in and took it.

That is the whole story in miniature, and it is not really a story about hackers. It is a story about where your personal information actually lives once you hand it over, who is holding it, and for how long. The people whose data was taken did not choose CEVA. Their retailers did. The record was doing exactly what the system is designed to make it do: travel from the company you bought from to the contractor that moves the box, and sit there, on a clock nobody asked you about.

The chain, one link at a time

Follow the data the way the goods travel, because they take the same road. A shopper buys something from an online retailer — in this case, among others, the Dutch stores Bol and De Bijenkorf, the eyewear maker Ace & Tate, and Valve's own hardware storefront. To deliver the item, the retailer passes the customer's name, home address, phone number and email to the company that runs its warehouse and shipping. That company is CEVA Logistics, one of the largest contract-logistics operators in the world and a subsidiary of the French shipping giant CMA CGM. CEVA holds those records across its European warehouse network. On July 29, according to the company's own disclosure, that network was breached. CEVA confirmed the intrusion on August 1.

Each handoff in that chain is individually unremarkable. A retailer cannot deliver a package without telling someone where you live. A logistics firm cannot run a warehouse without a database of shipments. None of it looks like surveillance at any single step. But stack the steps and you get the thing that actually broke: a single contractor holding the personal details of the customers of many unrelated retailers at once, in one system, behind one set of locks. The efficiency that makes outsourced logistics cheap — one operator serving dozens of brands — is the same property that turns one intrusion into a dozen companies' breach.

The spread bears that out. The records exposed reportedly touch customers of Bol, De Bijenkorf, Ace & Tate and Valve, and the fallout has reached further — the football club Ajax and the bank ING are among the organizations named in coverage of the incident. In the Netherlands, the Dutch data-protection authority has said it received breach notifications from ten separate organizations tied to the event. Ten companies, one warehouse contractor, one intrusion.

The efficiency that makes outsourced logistics cheap — one operator serving dozens of brands — is the same property that turns one intrusion into a dozen companies' breach.

What the records were, and what they were not

Precision matters here, because the temptation is to inflate. The data taken, according to the disclosures so far, is the ordinary exhaust of e-commerce delivery: names, home addresses, phone numbers, email addresses used for orders. Not payment-card numbers, on the current record. Not passwords. This is not the most sensitive category of data that exists. It is something arguably more durable: where you live, tied to your name and your phone, confirmed by the fact that you actually received a package there. It does not expire the way a card number does when you cancel the card. You cannot rotate your home address.

And here the record runs out in a way worth stating plainly. As of this reporting, no group has publicly claimed responsibility for the CEVA intrusion, and the company has not said whether it received a ransom demand or how many records in total were taken. CEVA has described only "a thorough investigation, which is still ongoing." So the attribution is unknown, the full scale is unknown, and anyone telling you otherwise is filling in a blank the evidence does not yet support. What is known is enough: the breach happened, it disrupted eight European warehouses, and it exposed the delivery records of customers who had no relationship with the breached company at all.

The same week, a different door

CEVA was not alone. In the same stretch of days, a hacking group calling itself Helix claimed to have breached Uber Freight, the freight-brokerage arm of Uber that matches shippers with trucking capacity. Google, which tracks the group as part of a cluster it labels UNC6671, has tied Helix to a string of intrusions at transportation companies, financial firms and private-equity shops, and estimated from the group's Bitcoin wallets that it collected at least $10.6 million in ransom payments between January and May of this year. Helix claims to have taken mailboxes, cloud-storage drives, accounts-payable files and dispatch documents from Uber Freight. The files a reporter at TechCrunch reviewed appeared to date from around mid-June. Uber Freight told Reuters there was "no effect on its business operations and that its systems were running normally," and has not said whether it was contacted by the hackers or paid anything.

The method is the part that should unsettle anyone who runs a large company, because there is nothing sophisticated about it. Helix, per Google, does not lean on exotic malware or an unpatched flaw. It calls the IT help desk on the phone, poses as an employee who needs a password reset, and talks its way in. The most valuable data in freight — who is shipping what, to whom, for how much — was reached, on this account, not by breaking the locks but by asking a human being for the key.

Put the two incidents side by side and the shared lesson is not about any one company's security team. It is about the shape of the target. Logistics is where the physical world and the data economy meet: every online order becomes a real box that has to reach a real address, which means every order generates a durable personal record that has to travel to whoever moves the freight. That record accumulates in a layer of the economy that consumers never see and cannot name — the brokers, the warehouse operators, the freight arms — and it is protected by whichever of them has the weakest help desk.

The ninety-day number is the policy

Return to the detail from the top, because it is the one a regulator should circle. CEVA held delivery data for ninety days after purchase. Valve did not need your address once your package arrived; the delivery was complete. But the address stayed, in the contractor's system, for three months, because in the plumbing of commerce retaining data is cheaper and easier than deleting it. Europe's own data-protection law contains a principle called data minimization — the idea that a company should keep personal information only as long as it genuinely needs it. The ninety-day window is what that principle looks like when it collides with operational convenience and convenience wins.

This is the structural fact underneath both breaches. The exposure was not created on July 29 by an intruder. It was created earlier, and quietly, by a hundred ordinary decisions to collect a little more, share it one link further, and hold it a little longer than the transaction required. The intruder only harvested what the system had already chosen to keep. A breach is the moment the accumulated data becomes visible; the accumulation is the thing that was always there.

What would actually change it

The reflex after an incident like this is to ask whether CEVA's or Uber Freight's security was good enough, and that question has its place. But it treats a structural condition as a series of individual lapses. The data economy's logistics layer will keep producing breaches like these for as long as its basic incentives hold, and those incentives are addressable. A few of them:

  • Delete on delivery. If a warehouse contractor does not need your address after the package arrives, the default should be that it is gone — days, not ninety of them. Minimization is already the law in Europe; the gap is enforcement against the intermediaries, not the storefronts.
  • Make the company you actually chose answer for the ones you didn't. A customer transacts with a retailer, not with its warehouse contractor. The retailer that hands your data down the chain should carry the accountability for what the chain does with it, rather than pointing to a subcontractor's breach as someone else's failure.
  • Treat a help-desk-resettable password on a system holding millions of addresses as a liability, not a convenience. The Uber Freight method worked because a phone call could reset a credential. Access to that volume of personal data should not survive a single spoofed call.
  • Name the intermediaries. Consumers cannot pressure, avoid, or hold accountable a company whose name they never learn. The layer of brokers and contractors that holds the most personal data operates in near-total public obscurity, and that obscurity is not an accident of the business. It is a feature of it.

None of that is exotic. It is the unglamorous work of making a system hold less, share less, and keep less — of narrowing the target rather than hardening every door around it. The breaches this month will be investigated as security incidents, and in the narrow sense they are. But the reason a single intrusion could reach the customers of ten companies, and the reason an address you gave a game store in the spring was still exposed in the summer, is not that someone failed to lock a door. It is that the data was there to take, held by a company you never chose, on a clock you never set. That was not the accident. That was the design.

References

  1. TechCrunch: A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
  2. The Record: Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe
  3. TechCrunch: Uber Freight reportedly investigating after hacking group claims data breach
  4. SecurityWeek: Ceva Logistics Operations Disrupted by Cyberattack
  5. Infosecurity Magazine: Logistics Giant Ceva Suffers Data Breach Impacting European Clients
The Friday Brief

One email. Every Friday.

The week's machines, money, and people — in under five minutes.