CEVA Logistics: one breach, a dozen brands you never gave your data to
A cyberattack on shipping giant CEVA Logistics, confirmed between July 29 and
August 1, 2026, exposed customer data belonging to Valve, football club Ajax, Bol.com,
Ace & Tate and others — none of whom were breached directly. All of
them simply shared a warehousing subcontractor.
⚠️ Read this before anything else. This isn't a
breach of Valve, Ajax, Bol.com, or any brand you might recognize. It's a breach of their
shared logistics subcontractor, CEVA — which happened to be holding their customers' data
for shipping purposes. The confirmed facts below concern CEVA's systems; each affected
brand's own security was not the point of failure.
The numbers, and their real status
8
Warehouses across Europe affected by the intrusion, between July 29 and August 1, 2026. Confirmed.
TechCrunch, The Record, 08/10–11/2026.
10+
Organizations that reported the incident to the Dutch data
protection authority as customers of CEVA.
The Register, 08/11/2026.
Aug 1
Date CEVA began notifying affected customers that stored goods
could not be shipped, and that data had been exposed.
TechCrunch, 08/10/2026.
0
Payment or credential data affected, according to reporting on the
incident.
Multiple outlets, 08/2026.
Timeline
CONFIRMED
July 29 – August 1, 2026
A cyberattack hits CEVA Logistics, disrupting operations at
eight warehouses across Europe. CEVA's air, ocean, ground and rail transport
operations continue normally; the disruption is limited to parts of its contract
logistics business.
CONFIRMED
August 1, 2026
CEVA notifies affected customers that goods stored at the
disrupted facilities cannot be shipped, and that personal data — names, addresses,
phone numbers, emails, order details, and for business customers, entity names and
identification numbers — may have been exposed.
CONFIRMED
August 10–11, 2026
The ripple effect becomes public: Valve (Steam hardware),
football club Ajax, Dutch retailers Bol and De Bijenkorf, eyewear chain Ace & Tate,
and Pokémon Center customers in Germany and the UK are all named as affected — none of
them breached directly, all of them CEVA clients. At least 10 organizations report the
incident to the Dutch data protection authority.
📦The lesson isn't about CEVA specifically
Every brand on this list did nothing wrong in the conventional sense — none of them
were hacked. Their mistake, if any, was structural: outsourcing warehousing and shipping
necessarily means handing customer data to a third party. When that party is breached,
the brand's own security posture is irrelevant. This is the supply-chain pattern that
keeps recurring across breach reporting: the weakest link is rarely the company whose
name is on the product.
What it changes for you
If you've ordered from any of the affected retailers recently, the exposed data —
name, address, phone, order details — is enough to make a fake delivery notification or
"problem with your shipment" message sound convincing. It's the same mechanism documented
in From Leak to Scam: the leak supplies
the credibility, the message supplies the urgency.
🔒 A message about a delivery you're actually expecting deserves
the same caution as one you aren't: verify through the retailer's own app or website,
never through a link in the message itself. See
how Medusa links channels together.
Frequently asked questions
Is the CEVA Logistics breach confirmed?
Yes. CEVA notified affected customers directly starting August 1, 2026, and at least
10 organizations reported the incident to the Dutch data protection authority. This is a
confirmed intrusion, not an unverified hacker claim.
Why were companies like Valve and Ajax affected if they weren't hacked?
Because CEVA is a shared shipping and warehousing subcontractor. The breach happened
inside CEVA's systems; the exposed data belonged to the customers of CEVA's clients.
None of these brands were breached themselves.
What should customers of these affected brands do?
Watch for messages referencing a recent order. Payment and login credentials were
not affected, so the risk is social engineering, not account takeover.
📌 Last checked: August 21, 2026. Verifiable
information to report: contact@egidio.app.
Cite this pageEgidio — The Threat Laboratory, "CEVA Logistics: one breach, a dozen brands you never gave your data to," egidio.app/en/laboratoire/ceva-logistics-europe-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.