The CEVA Logistics Breach: One Vendor’s Failure Simply Grew to become Six Manufacturers’ Downside
A single logistics vendor uncovered buyer knowledge belonging to a financial institution, a soccer membership, an e-commerce big, and one in every of gaming’s largest platforms inside the identical two-week window. Not one of the six manufacturers concerned suffered a direct breach. The failure sat one layer down, inside a warehouse operator most buyers have by no means heard of.
A Breach That Began in a Warehouse, Not a Retailer
Attackers compromised at the least eight European warehouses run by CEVA Logistics between July 29 and August 1, 2026, in keeping with reporting from TechCrunch and The Register. CEVA, a subsidiary of French delivery group CMA CGM since 2019, operates greater than 1,000 services throughout upward of 160 nations, based mostly on the corporate’s personal supplies as cited by TechCrunch and Wikipedia. TechCrunch put CEVA’s most up-to-date annual income at roughly $18.3 billion; CMA CGM’s 2025 group outcomes report $54.4 billion in whole income however don’t break CEVA out as a separate determine, in order that particular quantity couldn’t be checked towards a major submitting. CEVA confirmed the intrusion internally on August 1 and informed Dutch e-commerce firm Bol the identical day. The Dutch Information Safety Authority discovered of the incident on August 3.
Bol and division retailer De Bijenkorf, which share CEVA as a achievement companion, emailed clients the next week to warn that names, addresses, postcodes, and cellphone numbers linked to particular orders could have been accessed. Soccer membership Ajax, financial institution ING, and eyewear retailer Ace & Tate confirmed comparable publicity days later, in keeping with NOS and NL Instances. ING specified the incident impacts clients who redeemed loyalty factors for bodily merchandise, and Ajax informed followers to observe for phishing messages. Vogue retailer Zalando additionally reported disruption tied to CEVA, although it says no buyer knowledge was leaked in its case. Each firm concerned, together with Valve, says cost particulars, usernames, and passwords stay unaffected. The Dutch regulator confirmed it had acquired studies from at the least 10 organizations, with extra anticipated given CEVA’s footprint.
Why the Similar Vendor Retains Reappearing
The sample factors to a structural hole slightly than six separate safety failures. Retailers, banks, and platforms spend closely on hardening inside programs: encryption, multi-factor authentication, devoted safety groups. Few apply the identical scrutiny to the distributors who bodily transfer their merchandise, as a result of these distributors sit exterior the customer-facing model and infrequently get named in a privateness coverage anybody reads. CEVA held order knowledge for a number of unrelated corporations directly, so one compromised warehouse community become a wave of separate disclosures inside days, some involving leaked knowledge and others, like Zalando’s, involving disruption with out a confirmed leak.
Achievement companions see the identical knowledge regardless of how robust a consumer’s inside defenses are. ING’s presence on the record of affected organizations makes the purpose instantly: a financial institution with a mature safety program nonetheless is dependent upon a delivery companion it doesn’t management for a slice of buyer knowledge. The breach didn’t check ING’s defenses. It bypassed them totally.
The disclosure timeline raises a separate query. CEVA notified Bol and the Dutch regulator inside days, in step with the 72-hour window GDPR units for informing supervisory authorities. Clients waited roughly per week longer. Bol has mentioned it wished to substantiate the scope of the incident earlier than contacting individuals, slightly than sending repeated, incomplete updates. That reasoning holds up operationally, nevertheless it additionally means affected clients spent a number of days as potential phishing targets with out figuring out their data was uncovered.
The Actual Threat Behind the Uncovered Information
My take is that the quick monetary publicity right here is decrease than in a typical credential leak, since no firm concerned misplaced passwords or cost knowledge. The actual threat is extra focused. Attackers now maintain actual names tied to actual addresses and actual order particulars, which is precisely what makes a faux supply textual content or a spoofed return electronic mail convincing. Valve already warned Steam clients to anticipate impersonation makes an attempt referencing real order data, and Ajax informed followers the identical. Anybody who ordered from Bol, De Bijenkorf, or Steam {hardware} previously few months ought to deal with surprising supply texts and emails with extra suspicion than common, not as a result of their accounts are in danger, however as a result of scammers now have sufficient actual element to sound reputable.
Companies ought to take a colder lesson from this. Vendor threat assessments are inclined to deal with cost processors and cloud suppliers, and logistics companions dealing with private knowledge at scale not often get the identical audit rigor. Clients is not going to distinguish between a model’s breach and its logistics companion’s breach when deciding whether or not to belief the model once more.
The Dutch regulator expects extra disclosures as extra CEVA shoppers work by way of their very own reporting obligations. CEVA has not but defined how attackers compromised eight warehouses directly, and till it does, each firm nonetheless routing shipments by way of the identical community carries the identical publicity the final a number of found the laborious method.
The CEVA Logistics Breach: One Vendor’s Failure Simply Grew to become Six Manufacturers’ Downside
A single logistics vendor uncovered buyer knowledge belonging to a financial institution, a soccer membership, an e-commerce big, and one in every of gaming’s largest platforms inside the identical two-week window. Not one of the six manufacturers concerned suffered a direct breach. The failure sat one layer down, inside a warehouse operator most buyers have by no means heard of.
A Breach That Began in a Warehouse, Not a Retailer
Attackers compromised at the least eight European warehouses run by CEVA Logistics between July 29 and August 1, 2026, in keeping with reporting from TechCrunch and The Register. CEVA, a subsidiary of French delivery group CMA CGM since 2019, operates greater than 1,000 services throughout upward of 160 nations, based mostly on the corporate’s personal supplies as cited by TechCrunch and Wikipedia. TechCrunch put CEVA’s most up-to-date annual income at roughly $18.3 billion; CMA CGM’s 2025 group outcomes report $54.4 billion in whole income however don’t break CEVA out as a separate determine, in order that particular quantity couldn’t be checked towards a major submitting. CEVA confirmed the intrusion internally on August 1 and informed Dutch e-commerce firm Bol the identical day. The Dutch Information Safety Authority discovered of the incident on August 3.
Bol and division retailer De Bijenkorf, which share CEVA as a achievement companion, emailed clients the next week to warn that names, addresses, postcodes, and cellphone numbers linked to particular orders could have been accessed. Soccer membership Ajax, financial institution ING, and eyewear retailer Ace & Tate confirmed comparable publicity days later, in keeping with NOS and NL Instances. ING specified the incident impacts clients who redeemed loyalty factors for bodily merchandise, and Ajax informed followers to observe for phishing messages. Vogue retailer Zalando additionally reported disruption tied to CEVA, although it says no buyer knowledge was leaked in its case. Each firm concerned, together with Valve, says cost particulars, usernames, and passwords stay unaffected. The Dutch regulator confirmed it had acquired studies from at the least 10 organizations, with extra anticipated given CEVA’s footprint.
Why the Similar Vendor Retains Reappearing
The sample factors to a structural hole slightly than six separate safety failures. Retailers, banks, and platforms spend closely on hardening inside programs: encryption, multi-factor authentication, devoted safety groups. Few apply the identical scrutiny to the distributors who bodily transfer their merchandise, as a result of these distributors sit exterior the customer-facing model and infrequently get named in a privateness coverage anybody reads. CEVA held order knowledge for a number of unrelated corporations directly, so one compromised warehouse community become a wave of separate disclosures inside days, some involving leaked knowledge and others, like Zalando’s, involving disruption with out a confirmed leak.
Achievement companions see the identical knowledge regardless of how robust a consumer’s inside defenses are. ING’s presence on the record of affected organizations makes the purpose instantly: a financial institution with a mature safety program nonetheless is dependent upon a delivery companion it doesn’t management for a slice of buyer knowledge. The breach didn’t check ING’s defenses. It bypassed them totally.
The disclosure timeline raises a separate query. CEVA notified Bol and the Dutch regulator inside days, in step with the 72-hour window GDPR units for informing supervisory authorities. Clients waited roughly per week longer. Bol has mentioned it wished to substantiate the scope of the incident earlier than contacting individuals, slightly than sending repeated, incomplete updates. That reasoning holds up operationally, nevertheless it additionally means affected clients spent a number of days as potential phishing targets with out figuring out their data was uncovered.
The Actual Threat Behind the Uncovered Information
My take is that the quick monetary publicity right here is decrease than in a typical credential leak, since no firm concerned misplaced passwords or cost knowledge. The actual threat is extra focused. Attackers now maintain actual names tied to actual addresses and actual order particulars, which is precisely what makes a faux supply textual content or a spoofed return electronic mail convincing. Valve already warned Steam clients to anticipate impersonation makes an attempt referencing real order data, and Ajax informed followers the identical. Anybody who ordered from Bol, De Bijenkorf, or Steam {hardware} previously few months ought to deal with surprising supply texts and emails with extra suspicion than common, not as a result of their accounts are in danger, however as a result of scammers now have sufficient actual element to sound reputable.
Companies ought to take a colder lesson from this. Vendor threat assessments are inclined to deal with cost processors and cloud suppliers, and logistics companions dealing with private knowledge at scale not often get the identical audit rigor. Clients is not going to distinguish between a model’s breach and its logistics companion’s breach when deciding whether or not to belief the model once more.
The Dutch regulator expects extra disclosures as extra CEVA shoppers work by way of their very own reporting obligations. CEVA has not but defined how attackers compromised eight warehouses directly, and till it does, each firm nonetheless routing shipments by way of the identical community carries the identical publicity the final a number of found the laborious method.















