Menu
Browse

Cyber Incident Victim: Ace & Tate

Date

Jul 2026

Location

Netherlands

Status

Ongoing

Updated

2026-08-10 20:46

Timeline
Occurred
Jul 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending
Summary

A cyberattack on Ceva Logistics compromised part of its European contract logistics operations, affecting eight warehouses and leading to the theft of customers’ personal data including names, addresses, phone numbers and email addresses. The breach impacted several firms that rely on Ceva for shipping, among them the eyewear retailer Ace & Tate, which reported that its customers’ shipping information was exposed. Other affected parties included a major Dutch online retailer, a luxury department store, a football club, a banking group and a video‑game platform, all of whom noted potential delays or cancellations of orders. Ceva stated that the intrusion was confined to the eight warehouses, with no other global systems affected, and that it was working with authorities while the investigation continued. Dutch data protection officials said they had received breach reports from ten organizations linked to the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 29, 2026, FreightWaves reported that the cyberattack on Ceva Logistics began. Ceva Logistics confirmed on August 1, 2026, to affected customers that a cyber intrusion was impacting part of its European contract logistics operations. Upon identification, Ceva’s cybersecurity teams activated security protocols and launched a thorough investigation that remained ongoing. The company stated that the operational impact was limited to eight warehouses, with no other CEVA systems globally affected and all other operations continuing without incident. Ceva indicated that some of its affected applications and services had been restored and that it was cooperating with authorities. At the time of the article’s publication on August 10, 2026, Ceva’s website was not loading properly. Dutch authorities, including the data protection authority, were investigating the incident and had received data breach reports from ten organizations related to the Ceva breach.

Cyber Incident Image

The breach resulted in the theft of personal information, including names, home addresses, phone numbers, and email addresses used to place orders from Ceva’s systems. Several companies that rely on Ceva for shipping reported that their customers’ shipping information had been affected. Among these companies, the eyeglass maker Ace & Tate confirmed that customers’ shipping information was affected. Other affected entities mentioned in the source include the Dutch online retailer Bol, the luxury retailer De Bijenkorf, football club Ajax, banking giant ING, and Valve’s Steam hardware division. Bol warned that customer data may have been taken and expected delays and possible order cancellations. De Bijenkorf confirmed order delays following the theft of its customers’ data. Valve learned on August 7, 2026, that data had been taken from Ceva’s systems and notified customers who had recently purchased Steam hardware. Ceva’s spokesperson declined to disclose the volume of data taken or whether any ransom demand had been received. The Dutch data protection authority noted that it had received breach reports from ten organizations in connection with the incident.

Sources
Sources available to members
1 source