De Bijenkorf
Incident posture
Linked entities
- Victim
- De Bijenkorf
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
Ceva Logistics experienced a cyberattack that disrupted operations at eight European warehouses, leading to shipping delays for several retailers and exposing personal data of their customers. Affected parties include De Bijenkorf, Bol, Ajax, Ace & Tate, Steam hardware purchasers, and ING bank, with notifications issued and investigations underway.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 29 2026 the cyber intrusion that would later be attributed to Ceva Logistics began, according to reporting from FreightWaves, and by early August the company had identified unauthorized access to part of its European contract logistics operations. On August 1 Ceva notified affected corporate clients, including Bol, that a cyber intrusion was impacting eight warehouses across Europe, a disclosure that was subsequently echoed in a statement to TechCrunch where Ceva confirmed the activation of its security protocols and the launch of an ongoing investigation with outside specialists. The operational impact was confined to those eight facilities, causing shipping delays for retailers whose inventory was stored there, and leading to the temporary removal of affected products from sale as well as delays or cancellations of customer orders. Among the retailers affected was the Dutch luxury department store De Bijenkorf, which, according to local media reports, confirmed order delays following the theft of its customers’ data. The compromised Ceva systems contained personal information such as names, home addresses, telephone numbers, email addresses, order numbers, tracking details and purchase information, and Bol’s notification to its customers indicated that this data may have been viewed or copied by unauthorized parties; similar concerns were raised for De Bijenkorf’s clientele in the press coverage.
In response to the incident, Ceva’s cybersecurity teams implemented containment measures, worked with law‑enforcement and data‑protection authorities, and reported that some of its affected applications and services had been restored to online status, although its website experienced loading difficulties at the time of publication. The Dutch data protection authority confirmed receipt of breach reports from ten organizations linked to the Ceva incident, underscoring the breadth of the notification obligations triggered by the data exposure. De Bijenkorf, while not detailing its own internal remedial steps in the sources, publicly acknowledged the order delays and the potential compromise of customer shipment information, aligning its communications with the broader pattern of affected retailers advising consumers of possible data exposure and service disruption. Throughout the period covered by the reports, Ceva maintained that no other global systems were affected, that the investigation remained ongoing, and that it had not publicly attributed the attack or confirmed any ransom demand. The narrative concludes with the acknowledgment that the full scope of the breach, including the precise volume of data taken and the identities of the threat actors, remained undetermined at the time of the available disclosures.
Sources
Sources available to members: 2 sources.