Cyber Incident Victim: CEVA Logistics
Timeline
Summary
Ceva Logistics confirmed a cyber intrusion that impacted part of its European contract logistics operations. The attack affected at least eight warehouses, causing shipping delays and exposing customers’ personal data such as names, addresses, phone numbers, and email addresses for partners including Bol, De Bijenkorf, Ajax, ING, Ace & Tate, and Valve’s Steam users. The company said it activated security protocols, launched an investigation that is ongoing, restored some applications and services, and is working with authorities while the Dutch data protection agency noted receiving breach reports from ten organizations related to the incident.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 29, 2026, the cyberattack on Ceva Logistics began according to FreightWaves. On August 1, Ceva Logistics confirmed to affected customers that a cyber intrusion was impacting part of its European contract logistics operations. The company said that as soon as the incident was identified, its cybersecurity teams activated security protocols and launched a thorough investigation that remained ongoing. Ceva stated that the operational impact was limited to eight warehouses in Europe and that no other Ceva systems globally were affected, with all other operations continuing without incident. The company's website was not properly loading at the time of publication on August 10, 2026.

The hack affected at least eight warehouses across Europe used for shipping goods across the continent. Several companies that rely on Ceva for shipping reported that hackers took customers' names, home addresses, phone numbers, and email addresses used to place orders from Ceva's systems. Dutch online retail giant Bol said hackers gained access to systems of its warehousing partner Ceva and warned that customers' data may have been taken, expecting delays and some order cancellations. De Bijenkorf, a Dutch luxury retailer, confirmed order delays following the theft of its customers' data per local media. Football club Ajax, banking giant ING, and eyeglass maker Ace & Tate also reported that customers' shipping information was affected. Valve told customers on August 7 that it had learned data was taken from Ceva's systems and alerted purchasers of Steam hardware that their personal information had been taken, noting that Ceva stores shipping and delivery information for 90 days following an order.
Ceva said some of its affected applications and services were back online and that it was working with the authorities. Authorities in the Netherlands are investigating the incident. Mark Schenkel, a spokesperson for the Dutch data protection authority, told TechCrunch that the agency had received data breach reports from 10 organizations in relation to the incident. Ceva spokesperson Ryan Fisher would not answer TechCrunch's questions about the incident, including whether the company knows how much personal data was taken or if Ceva has received any communication from the hackers such as a ransom demand. The investigation launched by Ceva's cybersecurity teams remained ongoing as of the article's publication.
