CEVA Logistics
Incident posture
Linked entities
- Victim
- CEVA Logistics
- Threat actors
- 0 actors
- Sources
- 12 sources
Timeline
Summary
CEVA Logistics experienced a cyberattack that disrupted operations at at least eight of its European warehouses, leading to the exposure of customers' personal information including names, addresses, phone numbers, email addresses, and order details. The incident affected multiple clients such as Bol, De Bijenkorf, Ajax, ING, Ace & Tate, Valve’s Steam business, and the Pokémon Center, while payment card data remained secure. The company confined the impact to the affected warehouses, notified affected customers, and launched an ongoing investigation with regulatory authorities.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 29, 2026, CEVA Logistics experienced a cyberattack that disrupted operations at eight of its warehouses across Europe, according to multiple company statements and media reports. The attack persisted through August 1, 2026, during which time IT infrastructure and physical warehouse activities were affected, leading to delays in order processing and shipping. CEVA confirmed that the operational impact was limited to those eight warehouses and that no other CEVA systems globally were disrupted. The company notified affected customers of the cyber intrusion on August 1, stating that its cybersecurity teams had activated security protocols and launched an ongoing investigation. Authorities in the Netherlands, including the Dutch Data Protection Authority, began investigating the incident and reported receiving breach notifications from ten organizations related to the attack.
Several CEVA clients disclosed that personal information associated with their customers may have been accessed or copied during the breach. Bol, a Dutch online retailer, informed customers that data from two order‑processing systems used for its fulfillment center could have been viewed or copied, though Bol’s own systems were not affected. De Bijenkorf noted that the breach might involve names, addresses, email addresses, phone numbers, and online order details, and that VAT numbers could also have been exposed. Ajax, Ace & Tate, and ING reported that customer shipping information held by CEVA was potentially compromised. Valve told European Steam hardware buyers that names, street addresses, postal codes, cities, countries, telephone numbers, email addresses, and order specifics such as product type and price could have been taken, emphasizing that it could not determine precisely which records were obtained. Pokémon Center notified its UK and German customers that hackers may have obtained full names, mailing addresses, phone numbers, email addresses, and order details, and that some orders had been canceled due to the fulfillment issue.
In response to the breach, CEVA stated that it worked with external cybersecurity specialists and law enforcement to investigate the intrusion and that some affected applications and services were gradually restored. Bol suspended data exchanges with CEVA as a precaution, indicating that exchanges would resume only when it was safe to do so. De Bijenkorf similarly indicated that it would monitor the situation and resume normal data sharing when security assurances were met. Valve announced that it was pressing CEVA for a full scope of the stolen data and was notifying data protection authorities in the countries affected. Pokémon Center posted a banner on its website warning UK‑based users of possible delays and advised customers to remain alert for phishing attempts referencing recent orders.
The incident highlighted the reliance of multiple sectors on CEVA’s logistics services, with downstream effects reported across retail, banking, gaming, and sports organizations. No payment card data or credential information was reported as compromised by any of the affected parties. CEVA’s website experienced loading difficulties at the time of early media coverage, but the company confirmed that its global operations outside the eight European warehouses continued without interruption. The Dutch Data Protection Authority’s investigation remained active, and CEVA continued to cooperate with regulatory bodies as part of its ongoing response.
Sources
Sources available to members: 12 sources.