Cyber Incident Victim: De Bijenkorf
Timeline
Summary
A cyberattack on Ceva Logistics compromised the personal data of customers of several companies that use its shipping services, including Dutch luxury retailer De Bijenkorf. The breach exposed names, home addresses, phone numbers and email addresses, leading to order delays and potential cancellations for affected retailers while Ceva’s cybersecurity teams investigated the intrusion and worked with authorities.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 29, 2026, the cyberattack on Ceva Logistics began, targeting its European contract logistics operations. Ceva identified the intrusion and on August 1 confirmed to affected customers that a cyber incident was impacting part of its operations. The company stated that the operational impact was limited to eight warehouses in Europe and that no other CEVA systems globally were affected. The breach exposed personal information including names, home addresses, phone numbers, and email addresses of retail customers whose orders were processed through Ceva’s systems.

De Bijenkorf, a Dutch luxury retailer, confirmed through local media that it experienced order delays following the theft of its customers’ data in the Ceva incident. Other Dutch entities such as Bol, Ajax, ING, and Ace & Tate also reported that their customers’ shipping information was affected, with Bol warning of possible order cancellations. Authorities in the Netherlands opened an investigation and the Dutch data protection authority said it had received data breach reports from ten organizations linked to the Ceva attack.
Ceva’s cybersecurity teams activated security protocols immediately after detection and launched a thorough investigation that remained ongoing at the time of reporting. The company indicated that some of its affected applications and services had been restored and that it was cooperating with law‑enforcement agencies. Ceva’s statement to TechCrunch noted that it stores shipping and delivery information for ninety days following an order, which explains the window of data exposed in the breach.
