Ceva Logistics has confirmed a cyberattack that disrupted operations at eight European warehouses, causing shipment delays for multiple customers and potentially exposing customer information handled through the affected facilities.
The incident began on July 29, with Ceva notifying impacted customers on August 1 that warehouse operations had been disrupted and goods stored at the affected locations could not be shipped while recovery efforts were underway.
Warehouse disruption impacts multiple organizations
The attack affected contract logistics operations at eight Ceva warehouses in Europe. Several organizations have since acknowledged operational impact, including Dutch retailer Bol, department store De Bijenkorf, financial institution ING, eyewear company Ace & Tate, football club Ajax Amsterdam, and Valve, which relies on Ceva to distribute physical Steam hardware across Europe.
The incident caused shipping delays for customers whose orders were processed through the affected logistics facilities while Ceva worked to restore its systems.
Customer information may have been exposed
Several Ceva customers have stated that the cyberattack may have resulted in unauthorized access to customer information stored within Ceva’s logistics systems.
Bol said the incident involved two systems used to process orders from one of its fulfillment centers. According to the retailer, no Bol systems were compromised, but customer information processed through the affected Ceva location may have been viewed or copied.
De Bijenkorf said the potentially exposed information includes customer names, addresses, email addresses, telephone numbers, and online order details. Business customer information may also include company names and identification numbers. The retailer stated that payment card data, bank account numbers, usernames, and passwords were not affected.
Valve also notified customers that delivery-related information associated with physical hardware shipments in Europe may have been exposed. The company said Ceva retains shipping information for approximately three months for these deliveries.
Investigation continues
Ceva has not disclosed how attackers gained access to its systems, whether data was exfiltrated, or who was responsible for the intrusion. The total number of affected individuals has also not been announced.
The company continues working to restore impacted services while investigating the incident.
Ceva Logistics, a subsidiary of CMA CGM Group headquartered in France, operates more than 1,700 facilities across 170 countries, providing contract logistics, freight, and vehicle transportation services worldwide.
Previous cyber incidents
This is not the first cybersecurity incident involving Ceva Logistics. In 2025, the Coinbase Cartel extortion group claimed responsibility for two separate attacks targeting the company, although the relationship between those claims and the current incident is unknown.
Ceva Logistics had not issued any additional public statement at time of publication beyond customer notifications regarding the operational disruption.












