DMR News

Advancing Digital Conversations

CEVA Logistics Cyberattack Disrupts Eight European Warehouses and Exposes Customer Data

ByJolyen

Aug 12, 2026

CEVA Logistics Cyberattack Disrupts Eight European Warehouses and Exposes Customer Data

CEVA Logistics has confirmed a cyberattack affecting eight warehouses in Europe, disrupting shipments and exposing personal information belonging to customers of several companies that use its logistics services. The affected data includes names, home addresses, phone numbers, email addresses, and order-related information.

The attack began on July 29 and caused delays across affected warehouses, according to FreightWaves. CEVA told customers on August 1 that a cyber intrusion was affecting part of its European contract logistics operations and said no other systems globally were affected.

CEVA said some affected applications and services have since returned online while its investigation continues. The company is also working with authorities but has not disclosed how much personal information was taken or whether the attackers have made a ransom demand.

Retailers Warn Customers About Stolen Data

Dutch retailer Bol said hackers accessed systems operated by CEVA, its warehousing partner, while Bol’s own systems were not compromised. In its official security notice, the company warned that some customer data may have been viewed or copied and that the disruption could delay or cancel some orders.

Dutch luxury retailer De Bijenkorf also reported delays and the theft of customer information. Ajax, ING, and eyewear company Ace & Tate have separately said customer shipping information connected to CEVA was affected.

Valve also notified European customers who recently purchased Steam hardware after learning on August 7 that CEVA-held information had been stolen. The affected information included names, delivery addresses, phone numbers, email addresses, and hardware purchase details, while payment information, passwords, and Steam Guard credentials were not exposed.

Valve said CEVA retains the delivery information it receives for up to 90 days after an order. The company warned affected users to watch for fraudulent emails, text messages, and calls that could use stolen delivery information to impersonate Valve, Steam, or shipping companies.

Dutch Regulator Receives Multiple Breach Reports

CEVA is one of the world’s largest logistics providers, operating more than 1,000 warehouses globally and reporting $18.3 billion in revenue in 2025. Its official newsroom currently contains no dedicated public announcement about the August cyberattack, although the company has provided statements directly to affected customers and media.

The Dutch Data Protection Authority is also examining the incident. Spokesperson Mark Schenkel told TechCrunch that the regulator had received breach reports from 10 organisations connected to the CEVA attack.

CEVA said its cybersecurity teams activated security procedures after detecting the intrusion and that the investigation remains underway. Operations outside the eight affected European warehouses have continued normally, according to the company.


Featured image credits: Wikimedia Commons

For more stories like it, click the +Follow button at the top of this page to follow us.

Jolyen

As a news editor, I bring stories to life through clear, impactful, and authentic writing. I believe every brand has something worth sharing. My job is to make sure it’s heard. With an eye for detail and a heart for storytelling, I shape messages that truly connect.

Leave a Reply

Your email address will not be published. Required fields are marked *