CSIDB logo
Incident

bol.com

Incident posture

Attack window
Jul 2026
Location
Netherlands
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-26 18:59

Linked entities

Victim
bol.com
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jul 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending

Summary

A cyberattack on Ceva Logistics disrupted operations at eight of its European warehouses, causing shipping delays and exposing personal data of customers from several of its clients. Bol informed its users that hackers may have accessed names, addresses, contact details, order numbers and gift‑message data stored in the compromised Ceva systems and said it had paused data exchanges with the logistics provider while working to restore service. Other affected parties included De Bijenkorf, Ajax, Ace & Tate, ING and Valve, which warned European Steam hardware buyers that their names, addresses, phone numbers, email addresses and purchase information could have been viewed. Ceva confirmed the intrusion, activated its security protocols, launched an investigation with external experts and said some services were back online as authorities in the Netherlands examined the breach.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 29, 2026, Ceva Logistics experienced a cyber intrusion that began affecting part of its European contract logistics operations, according to reports from FreightWaves. The company’s internal security teams identified the breach and, on August 1, notified affected corporate clients, including the Dutch e‑commerce platform Bol, that a cyberattack was impacting systems used to process orders from one of Bol’s distribution centers. Ceva stated that the operational impact was limited to eight warehouses across Europe and that no other Ceva systems globally were affected. Following the notification, Ceva’s cybersecurity teams activated its security protocols and launched a thorough investigation that remained ongoing as of mid‑August.

Bol reported that the compromised Ceva systems contained customer and shipment information, and that an investigation found cybercriminals had gained access to two Ceva applications used for order processing, without affecting Bol’s own systems. As a precaution, Bol suspended data exchanges with Ceva and said it would resume only when it was safe to do so, while products stored at the affected locations were temporarily taken offline and some customer orders were delayed or canceled. Bol informed affected customers that information such as names, addresses, postal codes, telephone numbers, email addresses, order numbers, tracking details, purchase information and, in some cases, messages attached to gift cards may have been viewed or copied by unauthorized parties. Valve, the operator of Steam, said it learned on August 7 that data had been taken from Ceva’s systems and began notifying European customers who had purchased Steam hardware that their names, street addresses, postal codes, cities, countries, telephone numbers, email addresses and the type and price of the hardware they ordered could have been compromised, noting that Ceva retains such shipping and delivery information for up to 90 days after an order.

Other Ceva customers that reported impacts included the Dutch luxury retailer De Bijenkorf, the eyewear company Ace & Tate, the Amsterdam football club Ajax and the banking group ING, all of which noted that customer shipping information had been accessed and that they experienced order delays or cancellations. Ceva confirmed to TechCrunch that some of its affected applications and services had been restored and that it was cooperating with authorities, although its website was not loading properly at the time of the August 10 publication. The Dutch data protection authority said it had received breach reports from ten organizations linked to the incident, and Ceva declined to disclose whether it knew the volume of data taken or if any ransom demand had been made. No public attribution of the attack has been provided, and it remains unclear whether ransomware was deployed.

Sources

Sources available to members: 2 sources.

CSIDB