CSIDB logo
Incident

Ajax

Incident posture

Attack window
Jul 2026
Location
Netherlands
Status
Unknown
CIA posture
Available to members
Updated
2026-08-26 18:51

Linked entities

Victim
Ajax
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jul 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending

Summary

Ceva Logistics experienced a cyber intrusion that disrupted operations at eight of its European warehouses, leading to shipping delays for several of its clients and exposing personal data of their customers. The compromised systems contained names, addresses, contact details, order numbers and, in some cases, gift‑card messages, affecting retailers such as Bol, De Bijenkorf, Ace & Tate, the football club Ajax, Valve’s Steam hardware customers in Europe, and banking partner ING. Ceva confirmed the attack, activated its security protocols, launched an ongoing investigation, and reported that some affected services have been restored while authorities in the Netherlands continue to examine the incident.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On July 29, 2026, cybercriminals gained access to systems at Ceva Logistics, initiating a breach that would later affect at least eight warehouses across Europe. Ceva’s internal detection identified the intrusion, and on August 1 the company notified affected corporate clients that a cyber intrusion was impacting part of its European contract logistics operations. The notification stated that Ceva’s cybersecurity teams immediately activated security protocols and launched a thorough investigation that remained ongoing. The operational impact was confined to the eight European warehouses, with no other Ceva systems globally affected and all other operations continuing without disruption. Ceva confirmed that some of its affected applications and services were later restored while it continued to work with authorities.

The breach exposed personal data of customers belonging to several Ceva clients, including the Dutch e‑commerce platform Bol, the luxury retailer De Bijenkorf, the eyewear maker Ace & Tate, the banking group ING, and the Amsterdam football club Ajax, for which Ceva handles merchandise and online orders. Bol reported that hackers accessed two Ceva systems used to process orders from one of its distribution centers, potentially exposing names, addresses, postal codes, telephone numbers, email addresses, order numbers, tracking information, purchase details and, in some cases, messages attached to gift cards. Bol suspended data exchanges with Ceva as a precaution and noted that some customer orders were delayed or canceled. De Bijenkorf similarly confirmed order delays following the theft of its customers’ data. Ajax, ING and Ace & Tate each reported that their customers’ shipping information was affected, while Valve warned Steam hardware buyers in Europe that names, street addresses, postal codes, cities, countries, telephone numbers, email addresses and the type and price of purchased hardware may have been compromised.

In response, Ceva brought in outside cybersecurity specialists to assist with the investigation and continued to cooperate with law enforcement and data protection authorities, including the Dutch authority which reported receiving breach notifications from ten organizations linked to the incident. Valve said it learned on August 7 that data had been taken from Ceva’s systems and began notifying potentially affected Steam customers on August 10, advising them that the exact scope of the taken records could not be determined. Ceva stated that it had stopped the unauthorized access after discovering the breach and that some of its affected applications and services were back online, although its website experienced loading issues at the time of early press reports. The company declined to disclose how much personal data was taken or whether the attackers had made any ransom demand or extortion attempt, and no public attribution of the attack has been made. The incident remains under investigation, with Ceva maintaining that the operational impact is limited to the eight European warehouses and that all other logistics operations continue unaffected.

Sources

Sources available to members: 2 sources.

CSIDB