Ceva Logistics Cyberattack Disrupts European Retailers, Exposes Customer Data
Global freight and contract logistics provider Ceva Logistics has confirmed a cyber intrusion that disrupted operations at eight warehouses across Europe, delaying shipments for major retailers including Dutch e-commerce platform Bol, luxury department store De Bijenkorf, eyewear brand Ace & Tate, Amsterdam football club Ajax, and the European operations of Steam's hardware business. The company notified corporate clients earlier this month that attackers had compromised part of its contract logistics business, though Ceva has not publicly disclosed the incident, identified the threat actor, or confirmed whether a ransom demand was issued. Affected customers can use a email breach checker to determine whether their personal details appear in known leaks tied to this incident.
Bol disclosed the attack to its own customers after learning from Ceva on August 1 that cybercriminals had accessed two Ceva systems used to process orders from one of Bol's distribution centers. Potentially exposed data includes names, addresses, postal codes, telephone numbers, email addresses, order numbers, tracking information, purchase details, and in some cases gift card messages. Bol suspended data exchanges with Ceva as a precaution and temporarily delisted affected products, while some orders were delayed or canceled outright. The retailer stressed that its own systems were not compromised and that Ceva engaged external cybersecurity specialists to contain the breach.
De Bijenkorf issued a similar warning last week, telling shoppers that a cyberattack on one of its logistics providers had disrupted orders, returns, and refunds while potentially exposing customer information. The full scope of the breach, including the locations of the eight affected European warehouses, remains unclear. Customers who reuse credentials across services should immediately run them through a password checker to assess exposure and rotate any passwords tied to Bol, De Bijenkorf, or related retail accounts. The attack highlights the cascading risk of third-party logistics compromises, where a single provider breach can ripple across dozens of downstream retailers and consumer brands sharing integrated fulfillment infrastructure.