Ceva Logistics Cyberattack Disrupts European Warehouse Operations, Delays Customer Shipments

Ceva Logistics has confirmed a cyberattack affecting eight European warehouses, disrupting shipments and prompting several customers to warn of possible data exposure.
CEVA Logistics logo over a nighttime warehouse distribution center with parked trucks and a digital global network graphic in the background, illustrating a cyberattack impacting logistics operations.

Update (August 14, 2026): This article was updated to credit FreightWaves for first reporting that eight Ceva Logistics warehouses were affected by the cyberattack. The figure was attributed by FreightWaves to a source close to the investigation.


Ceva Logistics was hit by a cyberattack that disrupted operations at eight European warehouses, causing shipment delays for multiple customers and potentially exposing customer information handled through the affected facilities.

The incident began on July 29, with affected customers reportedly notified on August 1 that a cyber intrusion was impacting part of Ceva’s contract logistics operation. FreightWaves first reported that eight Ceva warehouses were affected, citing a source close to the investigation.

Warehouse disruption impacts multiple organizations

According to FreightWaves, the disruption was limited to eight Ceva warehouses in Europe, while the company’s air, ocean, ground, and rail transportation management operations continued without interruption. The impact varied between customers depending on their reliance on applications and services at the affected facilities.

Several organizations have since acknowledged operational or data-related impact, including Dutch retailer Bol and department store De Bijenkorf. Other organizations reportedly affected by the incident include ING, Ace & Tate, Ajax Amsterdam, and Valve, which relies on Ceva to distribute physical Steam hardware across Europe.

The incident caused shipping delays for customers whose orders were processed through the affected logistics facilities. Some applications and services at the warehouses have since reportedly been restored for certain customers as recovery efforts continue.

Customer information may have been exposed

Several Ceva customers have stated that the cyberattack may have resulted in unauthorized access to customer information stored within Ceva’s logistics systems.

Bol said the incident involved two systems used to process orders from one of its fulfillment centers. According to the retailer, no Bol systems were compromised, but customer information processed through the affected location may have been viewed or copied.

Bol temporarily suspended data exchanges with the logistics provider and said products stored at affected locations were taken offline, while some orders were canceled or delayed. The retailer said data exchanges would resume only after it was determined they could be conducted safely.

De Bijenkorf said the potentially exposed information includes customer names, addresses, email addresses, telephone numbers, and online order details. Business customer information may also include company names and identification numbers. The retailer stated that payment card data, bank account numbers, usernames, and passwords were not affected.

Valve also reportedly notified customers that delivery-related information associated with physical hardware shipments in Europe may have been exposed. The company said Ceva retains shipping information for approximately three months for these deliveries.

Investigation continues

Ceva has not publicly disclosed how attackers gained access to the affected systems, whether information was exfiltrated, or who was responsible for the intrusion. The total number of affected individuals has also not been announced.

FreightWaves reported that the incident was being investigated by the Dutch Data Protection Authority, other law enforcement agencies, and affected companies.

Ceva Logistics, a subsidiary of CMA CGM Group headquartered in France, operates a global logistics network providing contract logistics and air, ocean, ground, rail, and finished vehicle transportation services.

Previous cyber incidents

This is not the first cybersecurity incident involving Ceva Logistics. In 2025, the Coinbase Cartel extortion group claimed responsibility for two separate attacks targeting the company, although the relationship between those claims and the current incident is unknown.

Ceva Logistics had not issued a detailed public statement at time of publication explaining the scope or cause of the cyberattack.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site