Cyber Incident Victim: Ajax
Timeline
Summary
Ceva Logistics experienced a cyberattack that compromised part of its European contract logistics operations, leading to the theft of personal data from customers of several partner companies. The breach exposed names, addresses, phone numbers, and email addresses of individuals who had placed orders through retailers such as Bol, De Bijenkorf, Ace & Tate, and Valve’s Steam hardware buyers, as well as information linked to Ajax football club and ING bank. The attack disrupted operations at eight warehouses, causing shipping delays and order cancellations, while Ceva’s security teams launched an investigation and worked with authorities, and some services have since been restored.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 29 the hack began affecting at least eight Ceva warehouses across Europe, causing shipping delays. Ceva Logistics, a France‑headquartered shipping and logistics company with $18.3 billion revenue in 2025 and over a thousand warehouses worldwide, confirmed on August 1 that a cyber intrusion was impacting part of its European contract logistics operations. The company said the operational impact was limited to those eight warehouses and that all other CEVA systems globally continued without incident. As soon as the incident was identified, CEVA’s cybersecurity teams activated its security protocols and launched a thorough investigation that remained ongoing. The breach resulted in the theft of personal information—names, home addresses, phone numbers, and email addresses—used by customers to place orders through Ceva’s systems.

Several companies that rely on Ceva for shipping reported that their customers’ data had been taken. Dutch online retailer Bol stated that hackers gained access to systems of its warehousing partner Ceva and warned that customer data may have been taken, expecting delays and some order cancellations. De Bijenkorf similarly confirmed order delays following the theft of its customers’ data. Football club Ajax, banking giant ING, and eyeglass maker Ace & Tate also reported that customers’ shipping information was affected. Valve informed customers on August 7 that data had been taken from Ceva’s systems and alerted purchasers of Steam hardware that their personal information had been compromised. Ceva said some of its affected applications and services were back online and that it was working with the authorities; its website was not properly loading at the time of publication. Authorities in the Netherlands are investigating the incident, and the Dutch data protection authority has received data breach reports from ten organizations related to the event.
