CSIDB logo
Incident

Ace & Tate

Incident posture

Attack window
Jul 2026
Location
Netherlands
Status
Unknown
CIA posture
Available to members
Updated
2026-08-24 00:16

Linked entities

Victim
Ace & Tate
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jul 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending

Summary

A cyberattack on Ceva Logistics disrupted operations at eight of its European warehouses, leading to shipping delays for several retailers and exposing personal data of customers whose orders were processed through the affected systems. The breach compromised information such as names, addresses, phone numbers, email addresses, order numbers and purchase details for users of Bol, De Bijenkorf, Ajax, Ace & Tate and Steam hardware buyers, with some data also linked to banking clients. Ceva confirmed the intrusion, activated its security protocols, launched an ongoing investigation and reported that some services have been restored while authorities continue to examine the incident.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 29 2026 a cyber intrusion began affecting part of Ceva Logistics’ European contract logistics operations, ultimately disrupting activities at eight warehouses across the continent. Ceva notified its corporate clients of the intrusion early in August and on August 1 confirmed to affected customers that a cyberattack was impacting its systems, stating that its security protocols had been activated and a thorough investigation launched. The same day, Bol reported that Ceva had informed it of the breach and that an investigation found cybercriminals had accessed two Ceva systems used to process orders from one of Bol’s distribution centers. Valve began notifying European Steam customers on August 7 that information associated with purchases of physical Steam hardware may have been compromised because Ceva handles those shipments in Europe and retains delivery data for up to 90 days.

The operational impact included shipping delays and order cancellations for retailers whose inventory was stored at the affected facilities, with Bol, De Bijenkorf, Ace & Tate, Ajax and ING all confirming that customer shipping information had been taken. Bol warned that data stored in the compromised Ceva systems at the time of the attack may have been viewed or copied by unauthorized parties, potentially exposing names, addresses, postal codes, telephone numbers, email addresses, order numbers, tracking information, purchase details and, in some cases, messages attached to gift cards. Valve disclosed that the potentially compromised information for Steam hardware buyers included names, street addresses, postal codes, cities, countries, telephone numbers, email addresses and the type and price of the hardware ordered. De Bijenkorf similarly confirmed order delays following the theft of its customers’ data, while Ajax and ING reported that customers’ shipping information was affected.

In response, Ceva’s cybersecurity teams immediately activated security protocols and launched an ongoing investigation, enlisting outside cybersecurity specialists to assist. Bol suspended data exchanges with Ceva as a precaution, indicating they would resume only when it was safe to do so. Ceva reported that some of its affected applications and services were back online and that it was working with the relevant authorities. The Dutch data protection authority said it had received data breach reports from ten organizations related to the incident, and Ceva confirmed it was cooperating with those investigations. No further details about the attackers, ransom demands or the full scope of the data taken were disclosed by Ceva in the available sources.

Sources

Sources available to members: 2 sources.

CSIDB