Cyber Incident Victim: Bol
Timeline
Summary
Ceva Logistics experienced a cyber intrusion that disrupted part of its European contract logistics operations, affecting at least eight warehouses and causing shipping delays for goods moving across the continent. The breach exposed personal information—including names, home addresses, phone numbers and email addresses—of customers belonging to several firms that rely on the company for delivery, such as a major Dutch online retailer, a luxury department store, a football club, a banking group, an eyewear maker and Valve’s Steam hardware buyers. The company said it activated security protocols, launched an ongoing investigation, restored some applications and services, and is cooperating with authorities, while the Dutch data protection authority noted receiving breach reports from ten organizations linked to the incident.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The hack against Ceva Logistics began on July 29, as reported by FreightWaves. On August 1, Ceva confirmed to affected customers that a cyber intrusion was impacting part of its European contract logistics operations. Upon identification, Ceva’s cybersecurity teams immediately activated its security protocols and launched a thorough investigation that remained ongoing. Ceva stated that the operational impact was limited to eight warehouses in Europe, with no other global systems affected. At the time of the article’s publication on August 10, Ceva’s website was not loading properly.

Bol announced on its website that hackers had gained access to the systems of its warehousing partner Ceva. Bol warned that its customers’ personal data may have been taken in the breach. Bol also said that it anticipated delays and that some customer orders would be canceled as a result. Similar notices were issued by De Bijenkorf, Ajax, ING, Ace & Tate, and Valve regarding the compromise of shipping information. Valve specifically informed customers on August 7 that data had been taken from Ceva’s systems and alerted recent Steam hardware purchasers that their personal information was affected, noting that Ceva retains shipping and delivery details for 90 days after an order.
Ceva reported that some of its affected applications and services had been restored to online status. The company said it was working with the relevant authorities to address the incident. The Dutch data protection authority indicated it had received data breach reports from ten organizations linked to the Ceva attack. Ceva’s spokesperson declined to disclose the volume of personal data taken or whether any ransom demand had been communicated. The investigation into the cyber intrusion remained ongoing at the time of reporting.
