CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · Monday, August 10, 2026

TL;DR for CISOs: Someone else's breach was your problem today. Valve began notifying Steam hardware buyers in Europe that their shipping details were stolen in a cyberattack on its logistics partner, CEVA Logistics, and warned them to expect targeted phishing. LexisNexis pulled three services offline after unusual activity on servers run by a third-party vendor, choosing an outage over an open door. And researchers detailed a supply-chain compromise that poisoned a vendor data feed feeding seven BdThemes WordPress plugins, quietly minting rogue administrators on affected sites. The connective thread is dependence: the data you hand to a vendor and the code you let a vendor run inside your environment are both attack surface you do not fully control.

BOTTOM LINE FOR CISOS
  1. A vendor's breach becomes your customers' phishing wave. When shipping, billing, or support data leaks through a partner, attackers use the real details to impersonate you, so pre-draft the customer notice and the "we will never ask you to pay a fee" message now.
  2. Disconnecting fast is a valid control. LexisNexis chose a service outage over continued exposure. Decide in advance which systems you would take offline, who can make that call, and how you would keep the business running while you rebuild.
  3. Trusted code updates itself from vendor infrastructure you never see. The BdThemes attack required no plugin update, only a poisoned data feed. Inventory what third-party components in your stack phone home, and monitor admin accounts and privileged sessions for silent additions.
HIGH · LEAD STORY

Valve tells Steam hardware buyers their data was stolen in a breach at shipping partner CEVA Logistics

Key facts
  • Who was hit: Steam hardware customers in Europe, notified directly by Valve. The compromise was not at Valve but at CEVA Logistics, the partner that ships Steam Deck and other hardware to European buyers.
  • The vendor: CEVA Logistics is a subsidiary of the CMA CGM Group. Valve reported that attackers had access to CEVA systems between July 29 and August 1, 2026.
  • The timeline: Valve says it learned of the compromise on August 7 and began emailing affected customers on August 10. Because CEVA retains order data for up to 90 days, Valve notified everyone it could reasonably assume was affected.
  • Data taken: Names, addresses, phone numbers, email addresses, and the type and price of ordered products.
  • Data not taken: Valve says payment information, Steam passwords, and Steam Guard codes were not exposed, as CEVA did not have access to them.
  • The follow-on risk: Valve warned that customers may receive phishing by email, SMS, or phone that quotes their real address and order to appear genuine, then asks them to confirm a delivery, pay a small customs or redelivery fee, or sign in to "verify" an order.
  • Wider blast radius: CEVA had told multiple European retailers on August 1 that a cyberattack disrupted operations at several of its European warehouses, so Valve's customers are one affected group among others tied to the same vendor.

What happened

The data that fuels a scam does not have to come from your own systems. Valve holds payment details and Steam credentials, and none of that was in play here. What leaked was the mundane shipping information a logistics partner needs to put a box on a doorstep: a name, an address, a phone number, and what was ordered. In the hands of a fraudster, that is more than enough to sound convincing. The attacker who knows your address and your recent purchase can pose as the courier or the retailer and ask for a small fee or a login, and the request lands because the details are real.

This is a clean example of concentration risk in the supply chain. A single logistics provider sits behind many brands, so one intrusion produces notification duty and fraud exposure across all of them at once. Valve's response was orderly: it isolated the messaging to the affected customers, told them plainly what was taken and what was not, and pre-empted the phishing by describing the exact scripts to expect. The lesson is not that a game company was careless. It is that the weakest link in a customer's experience of your security may be a company they have never heard of.

Evidence

Two independent sources:

What this means for your team

Map the vendors that hold your customer data even when they never touch your core systems, and rank them by the number of customers each one could expose in a single incident. For the concentrated ones, agree breach-notification timelines and evidence-sharing terms in the contract, not in the middle of an incident. Then prepare the customer-facing side in advance: a template notice that states what a legitimate message from you will and will not ask for, and a public reminder that you never request payment to release a delivery. Doing this before an event turns a scramble into a script. If this is a live question for you, it is worth comparing notes with peers on third-party and vendor risk management rather than reinventing the playbook alone.

Action checklist
  1. Identify vendors that hold customer contact and order data, and flag any single provider whose breach would trigger mass customer notification.
  2. Confirm contractual breach-notification timelines and data-retention limits with logistics, billing, and support partners.
  3. Pre-draft a customer notice and a standing "we will never ask you to pay a fee or log in from a message" reminder for delivery and order scams.
  4. Brief fraud, support, and social teams so they can recognize and respond to a phishing wave that quotes real customer order details.
HIGH · SUPPORTING

LexisNexis pulls Diligence, Metabase API, and Newsdesk offline after vendor server activity

Key facts
  • The company: LexisNexis, a global data analytics provider whose legal, business, regulatory, and risk services are used by corporations, law firms, financial institutions, and government agencies.
  • The response: It took three services offline, Nexis Diligence, the Nexis Metabase API, and Nexis Newsdesk, after identifying unusual activity on servers hosted and managed by an unnamed third-party vendor.
  • The decision: In its customer notice, the company said it made an immediate decision to disconnect from the third-party systems to protect customers and contain the issue at its source.
  • The recovery: LexisNexis said it is working with a cybersecurity forensic firm and is rebuilding the affected systems in a new environment before restoring service. Nexis Solutions president Todd Larsen confirmed the details.
  • Not related to Metabase Cloud: The company stated that Nexis Solutions is not a Metabase Cloud customer and that its Nexis Metabase API has no connection to the Metabase Cloud SQL injection zero-day disclosed on August 6.
  • History: LexisNexis disclosed a breach affecting 364,000 people via private GitHub repositories in May 2025, and in March 2026 a threat actor stole and later leaked files after exploiting a flaw in its cloud infrastructure.

What happened

The notable part of this story is the choice, not the intrusion. Faced with suspicious activity on infrastructure it does not run itself, LexisNexis pulled the affected services down rather than watch and wait. That is an expensive decision. Diligence supports compliance and due-diligence work, and the data feeds behind these products are wired into customer systems, so an outage ripples outward. Taking them offline anyway signals a judgment that continued exposure was the larger risk, and that rebuilding in a clean environment was safer than trusting the compromised one.

It also underlines how much containment depends on a vendor you do not control. LexisNexis could disconnect, but the servers, the forensic picture, and the timeline sit partly with the third party that hosts them. The company was careful to separate this event from an unrelated Metabase Cloud vulnerability making news the same week, a useful reminder that similar-sounding names invite false links during an active incident. For a data broker with two prior disclosures in just over a year, the pattern worth watching is less any single flaw than the recurring exposure of data held in systems at the edges of its own estate.

Evidence

What this means for your team

Decide now which services you would take offline in response to a suspected compromise, and make sure someone has the authority to make that call under pressure. A containment plan that assumes you will keep everything running is not a containment plan. Extend that thinking to hosted vendors: for the third parties that run systems on your behalf, confirm you can force a disconnect, obtain forensic data, and rebuild in a clean environment without waiting on their timeline. Practice the trade-off between availability and containment as a tabletop, because the pressure to keep a revenue-generating service up is exactly what attackers count on.

Action checklist
  1. Pre-identify services you would take offline during a suspected breach, and name who is authorized to trigger a shutdown.
  2. For hosted vendors, confirm your rights to disconnect, obtain forensic evidence, and rebuild in a new environment.
  3. Run a tabletop on the availability-versus-containment trade-off so the decision is rehearsed, not improvised.
NOTABLE · SUPPORTING

Poisoned vendor data feed turns seven BdThemes WordPress plugins into a backdoor

Key facts
  • The vendor: BdThemes, a WordPress plugin developer. Wordfence disclosed a supply-chain compromise across seven of its plugins, and the WordPress.org team temporarily removed the affected downloads.
  • The reach: The affected plugins include Element Pack, with more than 100,000 active installs, plus Live Copy Paste, Pixel Gallery, Prime Slider, Smart Admin Assistant, Ultimate Post Kit, and Ultimate Store Kit. Their listings were closed on the WordPress directory as of August 7 or 8, pending review.
  • The mechanism: No plugin source code was changed. A bundled component named Biggopti fetches promotional banners as JSON from a cloud storage bucket. Attackers gained write access to that bucket and replaced the legitimate JSON with a malicious payload.
  • The flaw: A cross-site scripting weakness rated CVSS 5.4, present since a March 1, 2026 change, runs the injected payload in the browser of any logged-in administrator on every wp-admin page load.
  • The payload: The script creates a rogue administrator via the WordPress REST API, installs a PHP web shell, and adds hidden persistence modules, including a magic-login backdoor and a module that conceals the rogue accounts from the user list.
  • The wider link: The command-and-control infrastructure has been tied to two other recent WordPress supply-chain attacks, indicating a broader campaign rather than an isolated incident.

What happened

This attack sidesteps the defenses most teams rely on for plugins. Nobody pushed a malicious update, so a site that pinned versions or reviewed release notes gained nothing. The malicious content arrived through a data feed that a trusted plugin quietly fetches in the background, which means the code an administrator was running never changed, only the instructions it received. Because the payload executes in the administrator's own authenticated session, it inherits full privileges and can create accounts, drop a web shell, and hide its own tracks without tripping the usual signals.

The design choices show intent to persist quietly. Hidden administrator accounts, a login backdoor tied to a URL parameter, and a module that scrubs the rogue users from the admin list all aim at long-term, low-visibility access. The severity rating on the underlying flaw is only medium, which is a useful caution: a modest client-side bug becomes a serious problem once an attacker controls the data source that triggers it. The initiating failure here was upstream, at the vendor's cloud storage, and every downstream site inherited the consequences.

Evidence

What this means for your team

If your marketing or web team runs WordPress with any of the named plugins, treat affected sites as potentially compromised, not merely in need of an update. Look for administrator accounts you did not create, unexpected must-use plugins, and new files in the web directory, and rotate credentials once the site is clean. More broadly, take the pattern seriously: components that pull remote content into a privileged context are a live supply-chain path, so know which of your third-party plugins and integrations phone home, and restrict who and what can reach an admin session. This is a good topic to work through with peers on software supply-chain security, since the same design shows up well beyond WordPress.

Action checklist
  1. Inventory WordPress sites for the affected BdThemes plugins and treat any as compromised until reviewed.
  2. Hunt for unauthorized administrator accounts, hidden must-use plugins, and web shells, then rotate admin credentials after cleanup.
  3. Identify third-party components that fetch remote content into privileged contexts, and constrain outbound calls and admin-session access.
ALSO NOTABLE
  • A vishing campaign tied to the BlackFile-linked extortion group tracked as UNC6671 targeted hedge funds and private-equity firms, with reporting naming Point72, Millennium, Two Sigma, and Citadel among those approached through help-desk impersonation and adversary-in-the-middle phishing. BleepingComputer
  • North Carolina Ports confirmed a cyberattack that disrupted IT systems and forced manual operations at Wilmington, Morehead City, and the Charlotte Inland Port, with the US Coast Guard monitoring the response. BleepingComputer
  • CISA warned that a critical Progress LoadMaster flaw is now being actively exploited, raising the priority for any organization running the load balancer. BleepingComputer
  • IEH Corporation, a supplier of connectors used in the THAAD and Patriot programs, disclosed in an SEC filing that a phishing attack gave an intruder access to an employee's Microsoft 365 mailbox, with potentially export-controlled data exposed. The Register

FAQ

What data did the Valve and CEVA Logistics breach expose?

The stolen records include names, postal addresses, phone numbers, email addresses, and the type and price of Steam hardware ordered by customers in Europe. Valve says payment details, Steam passwords, and Steam Guard codes were not involved because CEVA Logistics did not hold that data, and affected customers do not need to change their Steam password.

Why did Valve customers receive phishing warnings?

The stolen shipping data lets attackers craft scams that quote a real name, address, and recent order. Valve warned customers to expect fake delivery, customs-fee, refund, or account-verification messages by email, SMS, or phone that impersonate Steam or delivery companies, and to treat any request for payment or login as fraudulent.

Was the LexisNexis outage caused by a data breach?

LexisNexis took its Diligence, Metabase API, and Newsdesk services offline after identifying unusual activity on servers run by an unnamed third-party vendor. It disconnected from those systems to contain the issue and is rebuilding them with a forensic firm. It has not confirmed data theft, and it says the incident is unrelated to the Metabase Cloud zero-day disclosed on August 6.

How does the BdThemes WordPress supply-chain attack work?

Attackers gained write access to a cloud storage bucket that feeds promotional banners into seven BdThemes plugins and replaced the legitimate JSON with a malicious payload. A cross-site scripting flaw rated CVSS 5.4 then runs the payload in the browser of any logged-in administrator, creating rogue admin accounts and installing a PHP web shell, with no plugin update or on-disk file change required.

What is the main CISO takeaway from the August 10 briefing?

Third-party and supply-chain exposure defined the day. A logistics vendor breach became a customer phishing problem for Valve, a hosting vendor's servers forced LexisNexis to pull core services offline, and a poisoned vendor data feed turned trusted WordPress plugins into a backdoor. Inventory the vendors that hold your data or run code in your environment, and plan for their incidents as if they were your own.

CISO Platform Breach Intelligence Team

Curated by Pritha Aash, Community Head, CISO Platform. Read more in the Breach Intelligence hub.

Stay ahead of the next breach

CISO Platform is a vendor-agnostic community where security leaders network, share, and learn.

Join the CISO Platform community (free)

Subscribe to the weekly newsletter

Visit the Breach Intelligence hub

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion