News briefing
CEVA Logistics intrusion halts eight European warehouses and exposes client customer data

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.
A cyberattack on the logistics firm's European contract logistics operations delayed deliveries and exposed shipping details held for clients including Bol, De Bijenkorf, ING and Valve; twelve organisations have reported to the Dutch regulator.
01 / What happened
France-headquartered CEVA Logistics suffered a cyber intrusion that began on 29 July 2026 and disrupted part of its European contract logistics business, according to TechCrunch and SecurityWeek. On 1 August the company told affected customers that the intrusion was affecting those operations, that the impact was limited to eight warehouses in Europe and that no other CEVA systems globally were affected, TechCrunch reported.
Goods stored at the affected sites could not be shipped while CEVA worked to restore services. SecurityWeek reported that the company's air, ocean, ground and rail transport management continued to operate. CEVA has not published a public statement on the incident and did not respond to requests for comment from The Record.
02 / Why it matters
The incident shows how a single logistics provider can concentrate risk for many brands at once. Retailers, a bank, a football club and a games company all learned of exposure through the same supplier, and several warned of delivery delays or cancellations as well as data loss.
One warehouse operator's breach became a notification problem for a dozen of its clients.
The locations of the eight warehouses have not been disclosed, and the number of individuals affected across all clients is unknown.
03 / Who is exposed
Organisations that confirmed or were reported as affected include:
- Dutch retailers Bol and De Bijenkorf, which warned of possible data exposure and order delays
- ING, Ace & Tate and Amsterdam football club Ajax, whose customers' shipping details were affected
- Valve, which began notifying European buyers of Steam hardware; TechCrunch reported CEVA keeps shipping data for 90 days after purchase
- Zalando, named by Dutch news agency ANP among the companies involved
Data reported as exposed includes names, home addresses, phone numbers, email addresses and order details; Valve also cited hardware type and price. De Bijenkorf and Bol said payment details, bank account numbers and passwords were not involved.
The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) told TechCrunch it had received breach reports from 10 organisations; by 12 August, ANP reported the figure had risen to twelve. The regulator declined to name them.
04 / Confirmed vs. claimed
Confirmed: intrusion from 29 July 2026; customer notification on 1 August; eight European warehouses disrupted; customer contact and order data exposed for multiple clients, per their own notices; twelve breach reports filed with the Dutch regulator.
Claimed / unconfirmed: No group has been publicly attributed, and it is unclear whether ransomware was deployed or a ransom demanded. The total number of affected people is not known. Valve told customers "We're pressing Ceva for the full scope" (via The Record). SecurityWeek notes the Coinbase Cartel extortion group claimed two separate attacks on CEVA in the previous year; no link to this incident has been established.
05 / What to do now
- Customers notified by Bol, De Bijenkorf, ING, Valve or other affected brands should expect targeted phishing, including fake delivery or refund messages that cite real order details.
- Do not share payment or login details in response to unsolicited delivery messages; contact the retailer through its official site or app.
- Companies using third-party logistics providers should map which customer data each provider holds, confirm retention periods, and check that contracts require prompt breach notification.
- Include logistics suppliers in incident-response planning, covering both data exposure and loss of warehouse operations.
Source log / 2026-0812-CV
- TechCrunch — A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond (10 August 2026) Secondary
- The Record — Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe (11 August 2026) Secondary
- SecurityWeek — Ceva Logistics Operations Disrupted by Cyberattack (12 August 2026) Secondary
- Accountant.nl (ANP) — Twaalf meldingen bij Autoriteit Persoonsgegevens na datalek CEVA (12 August 2026) Secondary