Menu
Browse

Cyber Incident Victim: Bol

Date

Jul 2026

Location

Netherlands

Status

Ongoing

Updated

2026-08-10 21:16

Timeline
Occurred
Jul 2026
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending
Summary

Ceva Logistics experienced a cyber intrusion that disrupted part of its European contract logistics operations, affecting at least eight warehouses and causing shipping delays for goods moving across the continent. The breach exposed personal information—including names, home addresses, phone numbers and email addresses—of customers belonging to several firms that rely on the company for delivery, such as a major Dutch online retailer, a luxury department store, a football club, a banking group, an eyewear maker and Valve’s Steam hardware buyers. The company said it activated security protocols, launched an ongoing investigation, restored some applications and services, and is cooperating with authorities, while the Dutch data protection authority noted receiving breach reports from ten organizations linked to the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The hack against Ceva Logistics began on July 29, as reported by FreightWaves. On August 1, Ceva confirmed to affected customers that a cyber intrusion was impacting part of its European contract logistics operations. Upon identification, Ceva’s cybersecurity teams immediately activated its security protocols and launched a thorough investigation that remained ongoing. Ceva stated that the operational impact was limited to eight warehouses in Europe, with no other global systems affected. At the time of the article’s publication on August 10, Ceva’s website was not loading properly.

Cyber Incident Image

Bol announced on its website that hackers had gained access to the systems of its warehousing partner Ceva. Bol warned that its customers’ personal data may have been taken in the breach. Bol also said that it anticipated delays and that some customer orders would be canceled as a result. Similar notices were issued by De Bijenkorf, Ajax, ING, Ace & Tate, and Valve regarding the compromise of shipping information. Valve specifically informed customers on August 7 that data had been taken from Ceva’s systems and alerted recent Steam hardware purchasers that their personal information was affected, noting that Ceva retains shipping and delivery details for 90 days after an order.

Ceva reported that some of its affected applications and services had been restored to online status. The company said it was working with the relevant authorities to address the incident. The Dutch data protection authority indicated it had received data breach reports from ten organizations linked to the Ceva attack. Ceva’s spokesperson declined to disclose the volume of personal data taken or whether any ransom demand had been communicated. The investigation into the cyber intrusion remained ongoing at the time of reporting.

Sources
Sources available to members
1 source