European shipping and logistics services have been thrown into turmoil after a Ceva Logistics cyberattack compromised parts of the company’s systems. The disruption began on July 29, and the operator said it is still working to bring affected services back online.
According to the latest customer communications reported by multiple organizations, the incident affected operations linked to warehouses in Europe. As a result, shipments of goods stored in those locations were paused, while some parties also warned that certain customer data might have been exposed.
What happened and when the disruption started
The operational problems were reported to have started on July 29. From that point, eight warehouses across Europe were reported as affected. This warehouse-level impact became visible in the supply chain when order processing and shipping activities tied to those sites were interrupted.
On August 1, Ceva Logistics informed affected customers about the cyber incident and the resulting pause in logistics. In the notices, the company indicated that goods stored in the impacted warehouses were not shipping during the disruption.
Which customers reported an impact
The disruption did not remain internal. Several organizations publicly confirmed that their customers were affected, including Dutch retailers Bol and De Bijenkorf, as well as ING, Ace & Tate, the Amsterdam football club Ajax, and game distributor Valve.
These organizations communicated details at the customer level, including delays in order shipments. In some cases, they also expanded on the likelihood that personal data related to orders might have been involved in the breach.
Warehouse and order-processing systems involved
One of the clearer explanations came from Bol. The company stated that the incident involved two systems used for processing orders from a fulfillment location connected to one of its centers. Importantly, Bol said its own internal systems were not affected.
However, Bol added that data belonging to customers whose orders were processed via that location may have been viewed or copied. This distinction matters: even when a retail brand’s own platforms are safe, upstream logistics systems can still create exposure for order-related information.
What data might have been exposed
According to De Bijenkorf, the potential data breach could include a range of customer and order details. The reported categories include names, home addresses, email addresses, phone numbers, and online order information.
For business customers, De Bijenkorf said that entity names and identification numbers may also have been exposed. This suggests the incident may have touched both consumer and corporate order records.
De Bijenkorf further reported what was not part of the incident. The organization said there were no payment details, no bank account numbers (IBANs), no credit card information, and no usernames or passwords involved in the problem.
Valve’s warning about delivery-related data
Valve also notified customers about possible data compromise. In its communications, the company indicated that delivery-related customer information was likely affected by the attack.
Valve’s delivery chain relies on Ceva for shipping physical hardware into Europe. The reporting also notes that the logistics provider retains shipping information for about three months, as described in multiple community posts referencing the situation.
While the details of how far Valve’s affected data was used downstream were not fully spelled out in the public reporting, the core point remained: data connected to delivery logistics can become part of the risk when order fulfillment systems are disrupted.
How the attackers accessed the systems remains unclear
Despite the confirmed operational disruption, the method of compromise has not been established in the available reporting. It is currently unclear how attackers gained access to Ceva’s systems, how many individuals may have been affected, and who was responsible for the incident.
These gaps are common early in cybersecurity incidents, especially when investigating intrusion paths, identifying impacted data sets, and assessing whether attackers extracted, viewed, or copied records.
Ceva Logistics scale and services
Ceva Logistics is a contract logistics provider headquartered in France and operating as part of the CMA CGM Group. The company runs more than 1,700 facilities worldwide and offers logistics services spanning air, ocean, ground, and finished vehicle transport.
Its services are used across a broad geographic footprint, supporting operations in 170 countries. With that level of reach, even a localized warehouse disruption can ripple across retailers, shipping partners, and customer order flows.
Previous incidents and extortion claims
This is not the first time Ceva Logistics has faced cyber-related trouble. The reporting indicates that last year an extortion group known as Coinbase Cartel claimed responsibility for two attacks against the company.
While claims do not always equate to verified intrusions, repeated public allegations can increase scrutiny from customers and regulators. They also underline the importance of resilient incident response and strong security controls in logistics environments, where uptime and data protection are tightly linked.
What customers and businesses can take from this
For organizations that rely on third-party logistics partners, the incident highlights an uncomfortable reality: disruptions may originate upstream. Even if a retailer’s own ordering portal is unaffected, downstream fulfillment systems can still impact customers—both through shipping delays and through the exposure of order-linked data.
In practice, affected parties typically focus on three tracks: restoring order processing and shipping, informing customers transparently about what might have been compromised, and confirming whether sensitive financial or credential-related information was involved.
In this case, multiple customer statements pointed to the absence of payment credentials and account data such as IBANs and credit cards, while still leaving room for exposure of contact and order details.
Ongoing uncertainty and updates
At the time of the reporting, it was not yet clear how the intrusion occurred or how widely personal data might have been impacted. SecurityWeek had reportedly contacted Ceva Logistics for additional information and indicated it would update the story if the company responded.
Until more details are confirmed—especially around the access method, the scope of affected records, and whether data was definitively extracted—customers and partners are likely to remain focused on shipment recovery and careful monitoring for communications related to potential data exposure.
Conclusion
The Ceva Logistics cyberattack shows how cybersecurity incidents can quickly become logistics incidents. With eight European warehouses affected, customer orders were delayed and some parties warned that delivery and order-related information may have been compromised. As investigations continue, the case serves as a reminder that modern supply chains depend on both operational continuity and strong data safeguards.
Source: https://www.securityweek.com/ceva-logistics-operations-disrupted-by-cyberattack/
