Ace & Tate
Incident posture
Linked entities
- Victim
- Ace & Tate
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
A cyberattack on Ceva Logistics disrupted operations at eight of its European warehouses, leading to shipping delays for several retailers and exposing personal data of customers whose orders were processed through the affected systems. The breach compromised information such as names, addresses, phone numbers, email addresses, order numbers and purchase details for users of Bol, De Bijenkorf, Ajax, Ace & Tate and Steam hardware buyers, with some data also linked to banking clients. Ceva confirmed the intrusion, activated its security protocols, launched an ongoing investigation and reported that some services have been restored while authorities continue to examine the incident.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 29 2026 a cyber intrusion began affecting part of Ceva Logistics’ European contract logistics operations, ultimately disrupting activities at eight warehouses across the continent. Ceva notified its corporate clients of the intrusion early in August and on August 1 confirmed to affected customers that a cyberattack was impacting its systems, stating that its security protocols had been activated and a thorough investigation launched. The same day, Bol reported that Ceva had informed it of the breach and that an investigation found cybercriminals had accessed two Ceva systems used to process orders from one of Bol’s distribution centers. Valve began notifying European Steam customers on August 7 that information associated with purchases of physical Steam hardware may have been compromised because Ceva handles those shipments in Europe and retains delivery data for up to 90 days.
The operational impact included shipping delays and order cancellations for retailers whose inventory was stored at the affected facilities, with Bol, De Bijenkorf, Ace & Tate, Ajax and ING all confirming that customer shipping information had been taken. Bol warned that data stored in the compromised Ceva systems at the time of the attack may have been viewed or copied by unauthorized parties, potentially exposing names, addresses, postal codes, telephone numbers, email addresses, order numbers, tracking information, purchase details and, in some cases, messages attached to gift cards. Valve disclosed that the potentially compromised information for Steam hardware buyers included names, street addresses, postal codes, cities, countries, telephone numbers, email addresses and the type and price of the hardware ordered. De Bijenkorf similarly confirmed order delays following the theft of its customers’ data, while Ajax and ING reported that customers’ shipping information was affected.
In response, Ceva’s cybersecurity teams immediately activated security protocols and launched an ongoing investigation, enlisting outside cybersecurity specialists to assist. Bol suspended data exchanges with Ceva as a precaution, indicating they would resume only when it was safe to do so. Ceva reported that some of its affected applications and services were back online and that it was working with the relevant authorities. The Dutch data protection authority said it had received data breach reports from ten organizations related to the incident, and Ceva confirmed it was cooperating with those investigations. No further details about the attackers, ransom demands or the full scope of the data taken were disclosed by Ceva in the available sources.
Sources
Sources available to members: 2 sources.