CSIPE

Published

- 21 min read

The Parcel Text Knows What You Bought


The Digital Fortress: Your Everyday Guide to a Safer Digital Life

Stay Safe Online Without Making It Your Second Job

The Digital Fortress (Second Edition)

A warm, plain-English guide for people with real lives and finite patience. Learn the handful of habits that genuinely protect your money, accounts, and family, and get honest permission to ignore the rest.

Buy the book now
The Anonymity Playbook: Digital Survival for Whistleblowers, Journalists, Activists, and Everyone Else

For People Who Cannot Afford to Get Privacy Wrong

The Anonymity Playbook (Second Edition)

A practitioner’s field manual for journalists protecting sources, whistleblowers, and activists. It explains how the surveillance actually works, what each technique costs you, and exactly where it fails.

Buy the book now
Secure Software Development: Practical patterns for building secure software

Write, Ship, and Maintain Code Without Shipping Vulnerabilities

Secure Software Development

A hands-on security guide for developers and IT professionals who ship real software. Build, deploy, and maintain secure systems without slowing down or drowning in theory.

Buy the book now
The Secure Harness: Shipping Production Code with AI Coding Agents

Use AI Coding Agents Without Losing Control of Your Codebase

The Secure Harness

A calm, practical guide to letting agents do useful work inside boundaries you set, enforce, and audit. Ships with 15 copy-pasteable artifacts: hook scripts, permission configs, release gates, and MCP templates.

Buy the book now
The AI Native Engineer: Build, Evaluate, and Ship AI Systems That Work in Production

Stop Shipping Demos. Start Shipping Systems.

The AI Native Engineer

Sixteen hands-on chapters, one real product. Grow it from a single model call into a retrieved, tool-using, observable, production-grade system, with evaluation treated as a habit from the first feature.

Buy the book now

A text arrives while you are waiting for a parcel. It uses your name, names the thing you bought, and quotes your street. The message says delivery failed and asks for €1.49 to rearrange it. Nothing about it feels random, because almost none of it is random.

That is the practical consequence of the cyberattack on CEVA Logistics, a company that stores goods and ships orders for other businesses. Valve warned European buyers of Steam hardware on 10 August 2026 that information needed for delivery was likely taken. The affected fields may include a customer’s name, address, phone number, email address, country, the type of hardware ordered, and its price. CEVA did not hold Valve passwords, Steam Guard codes, or payment details. (Help Net Security, The Record)

Several European businesses reported effects from the same incident, including Dutch retailer Bol, department store De Bijenkorf, eyewear company Ace & Tate, football club Ajax, and Valve’s Steam hardware operation. CEVA told TechCrunch that the incident affected part of its European contract-logistics operation at eight warehouses. As of 15 August 2026, CEVA had not publicly given a total number of people affected, explained how the intruders entered, or attributed the attack to a named group. (TechCrunch, The Record)

Here is the reassuring part. A criminal who knows what was in your parcel has not automatically entered your Steam account, bank account, or email. The stolen delivery record is dangerous because it makes a lie sound familiar. Your best response is therefore quite small: stop treating accurate personal details as proof that a message is genuine, and check parcel problems through the shop or courier route you opened yourself.

What happened at CEVA, and what remains unknown

CEVA Logistics sits behind brands most customers recognise. A shop takes the order and payment, then passes enough information to a warehouse and carrier to put the right box at the right door. That information can include the recipient’s full address, phone number for delivery updates, email address, order number, item description, price, and tracking details. The arrangement is ordinary. It also means that a company you have never dealt with directly may hold a detailed copy of your purchase.

CEVA said it confirmed a cyber intrusion on 1 August 2026 affecting part of its European contract-logistics operation. The company told TechCrunch that the operational impact was limited to eight warehouses, that other global operations continued, and that an investigation was under way. Freight and shipping operations at the affected sites suffered delays, while some retailers temporarily stopped data exchanges or took products offline. (TechCrunch, The Record)

Valve’s notice gives the clearest timeline for Steam buyers. The attackers had access to relevant CEVA systems between 29 July and 1 August 2026, Valve learned of the likely exposure on 7 August, and it began notifying customers on 10 August. CEVA can retain Steam delivery information for as long as 90 days after an order, so Valve contacted customers whose records it could reasonably assume were present rather than pretending it knew the exact set that had been copied. (Help Net Security, Malwarebytes)

For a Steam order, the possible exposure covers names, street addresses, postal codes, cities, countries, phone numbers, Steam-linked email addresses, and the type and price of the hardware. The Record reports that Bol warned about a wider set of shipping records in its part of the incident, including order numbers, tracking information, purchase details, and in some cases messages attached to gift cards. Different CEVA customers passed different fields into their warehouse systems, so the data exposed for one retailer should not be assumed to match every other retailer’s data. (The Record)

The omissions matter just as much as the list. Valve said CEVA had no access to payment information, passwords, Steam Guard codes, or information about other Steam purchases. Affected Steam customers do not need to reset a password merely because of this notice, according to Valve. Changing a good, unique password will not remove a name and delivery address from a stolen shipping record, and a rushed password reset can distract from the message scams that the exposed data actually makes easier. (Help Net Security)

The full scale remains unsettled. TechCrunch reported on 10 August that the Dutch data-protection authority had received breach reports from ten organisations connected to the incident. CEVA would not tell the publication how much information was taken or whether an attacker had made a ransom demand. The Record reported no public attribution and no confirmation of ransomware. Those gaps should stay gaps until CEVA, affected businesses, investigators, or regulators provide evidence. (TechCrunch, The Record)

A breach notice often invites two bad reactions. One person decides that everything is compromised and changes every password in a panic. Another sees that no card number was involved and throws the notice away. The useful middle is more precise: identify what the stolen record can help somebody fake, then protect the decision that fake message is trying to rush.

Why a delivery record makes a better lie

Most parcel scams begin with a guess. Millions of people are waiting for something, so a criminal sends “we missed your delivery” to millions of phone numbers and accepts that most recipients will ignore it. The cost of each attempt is tiny. Enough people happen to be expecting a parcel that the lie still finds a few receptive moments.

A stolen shipping record removes much of the guesswork. The message can address you by name, mention a Steam Deck or pair of glasses, use the correct town, and arrive soon after the genuine purchase. If tracking details were present, it may even refer to the carrier or delivery stage. Malwarebytes describes the likely follow-up as an email, text, or call that quotes real order details before asking for a customs fee, redelivery payment, delivery confirmation, or sign-in. (Malwarebytes)

Imagine that Maya ordered a Steam Deck as a birthday present. Two weeks later, a text says: “Maya, delivery of your €569 Steam hardware order to Lindenstraat 18 is on hold. Pay €1.49 by 18:00 to release it.” The amount looks too small to justify a long investigation, and the accurate details seem to prove that the sender can see the real order. Maya taps while making dinner.

The €1.49 may be only the entrance. A fake payment page can collect card details, the security number, a billing address, and a one-time code. A fake Steam sign-in can collect an account password and then ask for the current Steam Guard code. A caller can use the delivery story to persuade the recipient to install screen-sharing software or “confirm” a bank alert. The stolen parcel record supplies the setting; the victim supplies the secret that was absent from the breach.

This is why accurate information inside a message has become weak evidence. A genuine courier knows your address. A criminal holding a copied delivery row may know it too. A genuine shop knows what you ordered. The person reading that row knows the same thing. Familiar details prove that the sender obtained details somewhere, not that the sender currently works for the business named in the message.

Criminals also benefit from timing. A person waiting for an expensive parcel already expects updates and may worry about it being left outside, returned, or delayed. A small fee can feel cheaper than losing the delivery. Attackers do not need to invent fear from nothing; they borrow the mild concern already attached to a real purchase and add a short deadline.

The safest habit breaks that timing advantage. Leave the message alone, open the retailer’s app or website from your own bookmark, and check the order there. If a carrier genuinely needs a payment or address correction, the same problem should usually appear in the order history or tracking page reached independently. A message that collapses when you refuse its link did not deserve your money.

The warehouse is part of your trust chain

Online shopping feels like a relationship between you and a shop. Behind the screen, an order travels through payment processors, warehouse systems, carriers, address-validation services, customer-support tools, and sometimes returns companies. Each business receives the portion of information it needs to do its job. The box reaches your home because several computers agree on your identity, address, purchase, and delivery state.

That chain explains why Valve could protect its own account and payment systems while Steam buyers still received a breach notice. CEVA needed delivery details to ship the hardware. A compromise at the warehouse therefore exposed a useful portrait of the transaction without opening Valve’s password database. Bol similarly said its own systems were not affected, while two CEVA systems processing orders from one distribution centre had been accessed. (The Record)

Think of a restaurant cloakroom. The cloakroom does not have the key to your home or access to your bank, but it has your coat, a ticket number, and a good idea that you are inside the building. That narrow information is enough for a particular job and enough to support a particular deception. A warehouse record has the same character: limited compared with a full account, yet rich enough to make a delivery story believable.

Retention stretches the trust chain through time. Valve said CEVA can hold delivery information for up to 90 days after an order. That may support returns, delivery disputes, accounting, and warehouse operations, but it also means a customer can be exposed after the parcel is safely on a shelf at home. The business purpose and the security cost sit in the same database. (BleepingComputer, Help Net Security)

Customers cannot personally audit every warehouse that touches an order. Telling people to research a global supply chain before buying a games console would turn sensible caution into a second job. Shops remain responsible for choosing processors, limiting the fields they share, setting retention periods, and responding clearly when a partner loses data. CEVA and its corporate customers must establish the scope of this incident; the buyer cannot reconstruct it from a breach email.

You can still use the trust chain intelligently. Treat any outside company named in a breach notice as a clue about the kinds of messages that may follow. A shipping-company breach points toward parcel calls, tracking links, customs fees, and address checks. A payroll breach points toward salary and tax stories. A travel breach points toward reservation changes. The leaked context tells you which costume a later scam is likely to wear.

This approach is calmer than treating all communication as hostile. Normal deliveries can continue. Genuine courier updates can remain useful. The change is that a message does not get to authenticate itself by repeating information from the very database that was exposed.

How to check a parcel message without trusting it

The difficult part is rarely spotting a spelling mistake. Modern scam messages can be polished, and a copied order record can make them unusually specific. The dependable check happens outside the message. You compare its claim with a route that the sender did not choose for you.

Start with the shop. Open the retailer’s app from your phone screen, type the address you already know, or use a saved bookmark. Sign in there and look at the order status. For Steam account issues, Valve says support happens through its official help site rather than unsolicited email, Steam Chat, or Discord contact. A message can imitate a logo; it cannot alter the order page inside the real account unless the account itself has also been compromised. (Malwarebytes)

Check the carrier separately if the shop shows a real tracking number. Open the carrier’s official app or website yourself and type that number. Do not use the link or phone number in the unexpected text, even when its domain looks close to the real one. One extra letter, a swapped word, or a convincing page hosted under an unrelated address can disappear on a small screen.

A demand for a small payment deserves the same care as a demand for a large one. The low amount is part of the persuasion because it makes checking feel wasteful. Your card number is worth more than the proposed fee, and the fake page may ask for a bank approval that authorises something quite different. Read the bank’s confirmation screen for the merchant and amount rather than copying a code into the page that requested it.

Phone calls need an independent route too. Thank the caller, end the call, and ring the number printed in the retailer’s app, on the bank card, or on the carrier’s official website. Do not let the caller transfer you to a “security department,” because you are still inside the route they control. If your phone shows a familiar business name, remember that caller identification can be forged.

Family members can make this easier for one another. If somebody sends you a parcel warning and asks, “Does this look real?”, ask whether they opened the order independently rather than trying to judge the screenshot by appearance. That question works even when the message has perfect grammar and the right address. It moves the decision from design to evidence.

Keep one sentence in mind: details identify the order, while an independent route identifies the sender. The first can leak. The second is something you choose.

What affected Steam buyers should do now

If Valve sent you a CEVA notice, you have a narrower job than a typical account breach creates. Valve says no payment information, password, or Steam Guard code was exposed through CEVA, so a mass password-reset sprint does not address the stated incident. Focus first on parcel messages and calls that use your real delivery information. (Help Net Security)

  1. Keep the notice, but do not use its links as your permanent route: Read it for the affected fields and dates, then reach Steam through the app or an address you type yourself. A saved copy helps if the scope changes or a regulator later asks when you were notified.

  2. Warn the people who answer messages at that address: A partner, parent, housemate, or small-business receptionist may receive the call or see the text. Tell them that a caller could know the name, address, Steam hardware type, and price. One quiet warning now is better than trying to explain the breach while somebody is being rushed.

  3. Check every delivery claim outside the message: Open Steam purchase history, the retailer’s account page, or the carrier’s official tracking site independently. If the supposed problem does not appear there, leave the text alone. If it does appear, resolve it from that trusted page.

  4. Refuse surprise fees and sign-ins: Do not pay customs, redelivery, insurance, or address-correction charges through a link that arrived unexpectedly. Do not enter a Steam password or Steam Guard code on a page reached from a parcel message. A caller who asks for a code from your phone is asking for a key, regardless of the story around it.

  5. Watch the relevant card without replacing it by reflex: The reported Steam exposure did not include payment details. Look at transactions normally and enable bank alerts if you find them useful, but there is no evidence in the cited notices that every affected buyer must cancel a card. Replace it if you entered its details into a suspicious page or your bank sees misuse.

  6. Use a unique Steam password and Steam Guard for the risk they actually cover: These controls help if a later phishing page tries to steal account access. They do not erase delivery information already copied from CEVA. If your Steam password is reused elsewhere, change the reused accounts because reuse is its own problem, not because CEVA held the password.

  7. Report a convincing attempt: Forward suspicious messages through the reporting route offered by the retailer, carrier, phone provider, or national fraud service. If you paid or disclosed bank details, contact the bank through the number on your card at once. Fast contact can sometimes stop or dispute a transaction.

That sequence is enough. You do not need a credit-monitoring subscription merely because the exposed Steam fields included an address and order. The reports cited here do not say that CEVA held a national identity number or Steam payment card for those orders. Use more serious identity-theft steps if a later notice expands your exposed fields, an account is opened in your name, or your country’s data-protection authority advises them.

People affected through another CEVA customer should read that customer’s notice rather than copying Valve’s assumptions. Bol’s shipping records may contain fields that Steam’s did not, and each retailer may have a different retention window. The shared incident does not make every dataset identical.

If you already clicked, paid, or signed in

A click by itself is not a confession of disaster. What matters is what happened after the page opened. Closing a page without entering information creates a different problem from giving it a card, password, one-time code, or permission to install software. Start with the action you took, not the embarrassment you feel.

If you entered a card number, call the bank using the number on the physical card or in its official app. Tell them the details were entered into a suspected parcel-scam page and follow their advice about freezing or replacing the card. Review pending transactions, keep screenshots or messages, and ask how to report any unauthorised payment. Do not call a “bank number” supplied by the person who sent the parcel message.

If you entered a Steam password, go to Steam through the official app or typed address and change it. Change any other account using the same password, beginning with the email account that can reset Steam. Review authorised devices and recent account activity, keep Steam Guard enabled, and use Steam’s official recovery path if access has already changed. A criminal may ask for a current Steam Guard code after collecting the password, so never approve a prompt you did not initiate.

If you gave away an email password, treat that as the priority. Email often holds reset links for shopping, social, and financial accounts. Change the password from a device you trust, sign out other sessions where the service permits it, check forwarding rules and recovery details, then secure the accounts that depend on that mailbox. An unfamiliar forwarding rule can quietly copy future messages even after the password changes.

If you installed an app or let a caller control the screen, disconnect the device from the internet and contact a trusted technical person or the bank from another device. Remote-control software can expose much more than the original delivery record. Remove the program only after you know what was installed, because a rushed deletion can miss a second component or destroy useful evidence.

If you only clicked and the page asked for information you did not provide, close it and update the browser and device. Check the download folder for anything the page persuaded you to open. You do not need to wipe a phone solely because a web page loaded, but an unexpected app, configuration profile, browser extension, or security warning deserves proper attention.

Scammers may call again after a failed attempt. They can pose as the bank’s fraud team and cite the first conversation, or claim that a refund needs another code. The second caller benefits from knowing you were concerned enough to engage. Return to the independent route every time, even when the caller knows what happened five minutes earlier.

Shame helps the criminal by buying silence. Tell the bank, the account provider, and somebody you trust. A fast, plain account of what you entered is more useful than a perfect explanation of why the message looked convincing.

What businesses should learn from a parcel database

The customer action is simple, but the business lesson reaches further. Shipping data deserves protection based on what it can help an attacker do, not on whether a database column is labelled “password.” A joined record containing a person’s name, mobile number, address, item, value, and tracking state can support a highly credible fraud attempt even when no payment card sits beside it.

Retailers should ask which delivery fields a logistics partner truly needs and how long each field needs to remain available. A carrier needs an address while a parcel is moving. Customer service may need a record during a return or dispute. Keeping every field in an active warehouse system for a round number of days is convenient, but convenience should be tied to a documented purpose and a deletion test.

Separation matters too. A warehouse operator can design systems so one compromised application does not expose every brand, warehouse, and retention period. CEVA said the operational impact in this incident was limited to eight European warehouses and that other global systems were unaffected. As of 15 August, the public reporting does not explain which technical boundaries contained the incident, so the limit should be reported as CEVA’s statement rather than treated as an independent forensic conclusion. (TechCrunch)

Breach notices should describe the likely follow-up, not merely list database fields. Valve did this well by warning that messages may quote a genuine address, ask for a small customs or redelivery fee, or request a sign-in to verify an order. That translation gives a customer something they can recognise at breakfast. “Contact data was exposed” does not. (Help Net Security)

Support teams need the same preparation. When hundreds of customers receive a realistic delivery lure, they should find a clear notice through the real shop, a known route for checking an order, and staff who will not ask them to repeat sensitive information. Companies should monitor lookalike domains and fake support accounts connected to the incident, then remove or block them where possible.

Small shops may use only one fulfilment partner and have little bargaining power. They can still keep an inventory of who receives customer data, include incident-notification terms in contracts, avoid exporting unnecessary notes, and rehearse a customer notice. The useful question is concrete: if this partner lost its order table tonight, what story could somebody tell our customer tomorrow morning?

Customers cannot fix those systems. Businesses should not turn “stay alert” into a way of handing the whole burden back to the person whose address was copied. Clear scope, prompt notification, short retention, sensible separation, and easy support belong to the organisations that collected and shared the information.

The one habit worth keeping

The CEVA incident shows why a scam can know the truth and still be a scam. Real order data can travel from a shop into a warehouse, remain there after delivery, and leave through a breach. A later message can repeat that truth while lying about who sent it and what you need to do next.

For Steam buyers, the known exposure is limited in an important way. Valve says CEVA did not have payment information, passwords, Steam Guard codes, or details of other purchases. That boundary should prevent unnecessary panic. The copied delivery fields still give a criminal enough material to stage a convincing parcel problem, especially during the 90-day period in which CEVA may retain records. (Help Net Security)

As of 15 August 2026, nobody outside the investigation can responsibly say how many records were taken, how the attackers entered, or whether every potentially present record was copied. The companies and regulators need to settle those questions. You can protect the decision in front of you without waiting for the forensic report.

Open the shop or courier yourself. Check the order there. Call back on a number you already trust. Read a bank approval before accepting it. If the message says you have sixty seconds to act, give yourself five minutes instead.

That is the habit worth keeping after this breach fades from the news: personal details make a story plausible, but they no longer prove who is telling it. The loyalty points, dark-web searches, and grand home-security project can wait. Check the parcel through your own front door, and you have my blessing to ignore the text.

If you want calm, practical security notes without the daily panic cycle, the newsletter is one email per month.

Sources