SINGAPORE, 10 AUG 2026 — Three sets of breach notifications went out this week. Not one of the companies sending them had been broken into.

Valve told European buyers of Steam hardware their delivery details were taken. Framework told every customer it had. LexisNexis pulled services offline. In each case the intrusion happened somewhere else: at a company the customer has no relationship with, did not choose, and, in two of the three cases, still cannot name.

One logistics vendor, several brands

Diagram of three intrusions in one week, each at a supplier rather than at the companies that notified customers: Metabase, whose zero-day exposed Framework and Tally; CEVA Logistics, whose compromise reached Valve, bol, De Bijenkorf and Ajax and disrupted eight European warehouses; and an unnamed third-party host, over which LexisNexis disconnected systems and took Nexis services offline.
Three intrusions, three suppliers, and a dozen or more consumer-facing brands doing the explaining. In two of the three the customer still cannot name the company that lost their data. RECATOOLS diagram.

Attackers were inside CEVA Logistics between 29 July and 1 August. CEVA is a freight and contract-logistics business owned by CMA CGM; most people whose data it holds have never heard the name.

Valve says CEVA receives delivery information from Steam in order to ship physical hardware in Europe, and that the attacker likely took exactly that: names, addresses, phone numbers, email addresses, and the type and price of the product ordered. Payment details, passwords and Steam Guard codes were not involved, because CEVA never held them. Valve was told on 7 August and notified customers on the 10th.

Valve is not the only one. The Dutch retailer bol has disclosed a breach through the same logistics partner, and reporting places De Bijenkorf and the football club Ajax in the same incident. Eight CEVA warehouses in Europe had operations disrupted over that weekend, with shipping delays for retail customers whose stock sits in them. The Dutch data protection authority is investigating.

One intrusion at one supplier produced a disrupted supply chain and a flurry of notifications from brands forced to explain a partner most of their customers had never heard of.

The one we got wrong, and the name that caused it

On Sunday we reported the Metabase zero-day that took Framework's and Tally's customer data. In that report we wrote that one outlet had named LexisNexis as affected through a third-party vendor, that we could not corroborate it, and that we had left it out.

That caution was warranted, for a reason that has become a pattern.

LexisNexis has confirmed it took Nexis Diligence, Nexis Newsdesk and its Nexis Metabase API offline this week after identifying, in its words, "unusual activity on servers that are hosted and managed by a third-party vendor." It disconnected from those systems, brought in a forensics firm, and is rebuilding in a new environment before restoring service.

And Todd Larsen, president of its global Nexis Solutions division, has explicitly ruled out the link: Nexis Solutions is not a Metabase Cloud customer, and the Nexis Metabase API has no connection to Metabase Cloud or to the vulnerability we reported.

The false link came from a name. LexisNexis sells a product called Metabase — a news and content API, unrelated to the open-source business-intelligence tool of the same name. A company with a product called Metabase went dark in the same week a company called Metabase was breached, and the inference wrote itself.

First, we have no basis to connect these incidents and are correcting the record here. Second, this is exactly how errors breed in a supplier incident: the company at the centre often goes unnamed, leaving everyone else to guess at the facts.

What the customer is actually exposed to

This is fourth-party risk. It matters because every consent flow a customer clicks describes a relationship that ends one hop short of where the data actually goes.

Somebody bought a Steam Machine. They dealt with Valve. Valve needed a courier, the courier needed an address, and the address is now with whoever was inside CEVA in late July. Nothing in that chain was hidden or improper. It is also entirely invisible from where the customer stands, and no amount of care on their part touches it.

Even seemingly dull data creates real exposure. Delivery details — a real order, product, price and delivery window — are what make a phishing message land. Valve said as much in its notice, warning customers to expect scam messages referencing their purchase. A stolen address list becomes a credible-sounding email in a way a stolen password hash does not.

Why vendor questionnaires do not see this

Most organisations manage supplier risk with an annual questionnaire and a certificate. Both describe a supplier's posture at a moment, and neither says anything about the supplier's own suppliers.

Look at what would have had to be on the form. For Framework: whether the hosted analytics vendor would have an unpatched authentication flaw four months later. For Valve: whether the courier's order-processing systems would be reachable over a specific weekend. Neither is knowable in advance. The control most companies rely on is not a control; it is a record that somebody asked a question once.

The only real lever is unglamorous: reduce what leaves in the first place. Every field handed to a supplier is a field that supplier can lose, and the question with real leverage is not how good their security is but why they have the phone number at all.

What actually helps

Minimise at the boundary. A courier needs a delivery address and a contact number; it does not need an order history or a price. An analytics vendor needs the columns the dashboard reads, not the whole table. This is the one decision that survives a vendor being compromised.

Set expiry on what you send. Delivery data has a natural life of a few weeks and is often kept for years, because nobody wrote down when it should go.

Write the notification path before you need it. Valve heard on the 7th and told customers on the 10th, which is quick for a chain that ran through another company's forensics. That gap is where a plan either exists or does not.

And keep a list of who holds what. Most companies cannot produce, in an afternoon, the set of suppliers holding customer personal data and which fields each one has. Without it the first hour of a vendor incident is spent working out whether you are affected at all.

What to watch

Whether more CEVA customers disclose. Four brands and eight warehouses in one week suggests a supplier list longer than the one that has spoken.

Whether LexisNexis names its vendor, and whether the "unusual activity" turns into a confirmed data incident. For now it is a company disconnecting from a supplier as a precaution. That is all anyone can say.

And whether any regulator treats the supplier as the reportable party. Under the current pattern the burden of explaining lands on whoever holds the customer relationship, which is neither where the failure happened nor where the fix has to be made.