Egidio
Case file · August 21, 2026

CEVA Logistics: one breach, a dozen brands you never gave your data to

A cyberattack on shipping giant CEVA Logistics, confirmed between July 29 and August 1, 2026, exposed customer data belonging to Valve, football club Ajax, Bol.com, Ace & Tate and others — none of whom were breached directly. All of them simply shared a warehousing subcontractor.

⚠️ Read this before anything else. This isn't a breach of Valve, Ajax, Bol.com, or any brand you might recognize. It's a breach of their shared logistics subcontractor, CEVA — which happened to be holding their customers' data for shipping purposes. The confirmed facts below concern CEVA's systems; each affected brand's own security was not the point of failure.

The numbers, and their real status

8
Warehouses across Europe affected by the intrusion, between July 29 and August 1, 2026. Confirmed.
TechCrunch, The Record, 08/10–11/2026.
10+
Organizations that reported the incident to the Dutch data protection authority as customers of CEVA.
The Register, 08/11/2026.
Aug 1
Date CEVA began notifying affected customers that stored goods could not be shipped, and that data had been exposed.
TechCrunch, 08/10/2026.
0
Payment or credential data affected, according to reporting on the incident.
Multiple outlets, 08/2026.

Timeline

CONFIRMED
July 29 – August 1, 2026
A cyberattack hits CEVA Logistics, disrupting operations at eight warehouses across Europe. CEVA's air, ocean, ground and rail transport operations continue normally; the disruption is limited to parts of its contract logistics business.
CONFIRMED
August 1, 2026
CEVA notifies affected customers that goods stored at the disrupted facilities cannot be shipped, and that personal data — names, addresses, phone numbers, emails, order details, and for business customers, entity names and identification numbers — may have been exposed.
CONFIRMED
August 10–11, 2026
The ripple effect becomes public: Valve (Steam hardware), football club Ajax, Dutch retailers Bol and De Bijenkorf, eyewear chain Ace & Tate, and Pokémon Center customers in Germany and the UK are all named as affected — none of them breached directly, all of them CEVA clients. At least 10 organizations report the incident to the Dutch data protection authority.

📦The lesson isn't about CEVA specifically

Every brand on this list did nothing wrong in the conventional sense — none of them were hacked. Their mistake, if any, was structural: outsourcing warehousing and shipping necessarily means handing customer data to a third party. When that party is breached, the brand's own security posture is irrelevant. This is the supply-chain pattern that keeps recurring across breach reporting: the weakest link is rarely the company whose name is on the product.

What it changes for you

If you've ordered from any of the affected retailers recently, the exposed data — name, address, phone, order details — is enough to make a fake delivery notification or "problem with your shipment" message sound convincing. It's the same mechanism documented in From Leak to Scam: the leak supplies the credibility, the message supplies the urgency.

🔒 A message about a delivery you're actually expecting deserves the same caution as one you aren't: verify through the retailer's own app or website, never through a link in the message itself. See how Medusa links channels together.

Frequently asked questions

Is the CEVA Logistics breach confirmed?

Yes. CEVA notified affected customers directly starting August 1, 2026, and at least 10 organizations reported the incident to the Dutch data protection authority. This is a confirmed intrusion, not an unverified hacker claim.

Why were companies like Valve and Ajax affected if they weren't hacked?

Because CEVA is a shared shipping and warehousing subcontractor. The breach happened inside CEVA's systems; the exposed data belonged to the customers of CEVA's clients. None of these brands were breached themselves.

What should customers of these affected brands do?

Watch for messages referencing a recent order. Payment and login credentials were not affected, so the risk is social engineering, not account takeover.

📌 Last checked: August 21, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio — The Threat Laboratory, "CEVA Logistics: one breach, a dozen brands you never gave your data to," egidio.app/en/laboratoire/ceva-logistics-europe-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.