ctipilot.ch

CEVA Logistics European fulfilment-systems breach (August 2026)

incident · incident:ceva-logistics-fulfilment-breach-2026-08

Intrusion into order-processing systems at CEVA Logistics, the contract-logistics arm of CMA CGM, which the company confirmed to affected customers on 1 August 2026 and scoped to eight European warehouses. Because CEVA processes fulfilment data for unrelated clients, the compromise produced independent GDPR notification duties at ten organisations, confirmed by the Dutch data protection authority; named affected parties include ING, bol.com, De Bijenkorf, AFC Ajax, Ace & Tate and Valve. bol.com states two order-processing systems at one fulfilment centre were involved and that customer data may have been viewed or copied. No initial-access vector, malware family or actor has been disclosed by any party, CEVA has published no statement of its own, and it disputes that a dataset offered on a criminal forum relates to this incident (bol.com, 2026-08-06; TechCrunch, 2026-08-10; ICTMagazine.nl, 2026-08-10).

Aliases: CEVA Logistics order-processing breach 2026

Coverage timeline
1
first 2026-08-11 → last 2026-08-11
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-08-11/ceva-logistics-fulfilment-breach-ten-controllers-notified · ATT&CK page ↗

Story timeline

  1. 2026-08-11One compromised contract-logistics processor put ten organisations into breach notification at once — CEVA Logistics, eight European warehouses, and a bank, a retailer and a games platform all learning from their supplier
    active-threatsTen organisations filed Dutch breach reports over one logistics provider's order-processing intrusion

Where this entity is cited

  • active-threats1

Source distribution

  • ictmagazine.nl1 (33%)
  • partnerplatform.bol.com1 (33%)
  • techcrunch.com1 (33%)

explore in graph

Entries about CEVA Logistics European fulfilment-systems breach (August 2026) (1)

2026-08-11 · view entry permalink →

NOTABLENATOB1

One compromised contract-logistics processor put ten organisations into breach notification at once — CEVA Logistics, eight European warehouses, and a bank, a retailer and a games platform all learning from their supplier

CEVA Logistics — a contract-logistics operator that has been part of the French shipping group CMA CGM since 2019 (ICTMagazine.nl, 2026-08-10) — confirmed to affected customers on 1 August 2026 that a cyber intrusion was affecting part of its European contract-logistics operations, telling TechCrunch that its security teams activated protocols and opened an investigation that is still running, and that the operational impact was limited to eight warehouses, with no other CEVA systems globally affected (TechCrunch, 2026-08-10). That is the whole of what the compromised party has said publicly. Dutch trade reporting records that CEVA itself has given no public reaction of its own to these incidents (ICTMagazine.nl, 2026-08-10), and its spokesperson declined to answer whether the company knows how much personal data was taken or whether it has heard from the intruders at all, including on a ransom demand (TechCrunch, 2026-08-10).

The reason this is an entry rather than one more breach is arithmetic. CEVA processes fulfilment and shipping data for many unrelated clients, so one intrusion at one processor created independent notification duties at each of them simultaneously: the Dutch data-protection authority's spokesperson confirmed to TechCrunch that it has received breach reports from ten organisations in relation to this single incident. The named downstream parties span sectors that share nothing but a logistics contract — ING in banking, bol.com and De Bijenkorf in retail, the football club AFC Ajax, the eyewear retailer Ace & Tate, and Valve, which told customers it learned on 7 August that data was taken from CEVA's systems and alerted customers who had recently bought its Steam hardware, noting CEVA holds their shipping and delivery information for 90 days after an order (TechCrunch, 2026-08-10); Dutch trade reporting scopes those Steam buyers to Europe (ICTMagazine.nl, 2026-08-10).

bol.com's own notice is the most specific account any party has published. It records that it was informed on 1 August, that the incident involves two systems used for processing orders from one of its fulfilment centres, that no bol systems were affected, and that data of customers whose orders were processed via that location may have been viewed or copied (bol.com, 2026-08-06). It also records the containment sequence — the logistics partner moved to stop the unauthorised access and brought in external specialists, and bol proactively halted data exchange with it pending assurance that resuming is safe — and the part that is easy to miss in a data-breach framing: the affected location's stock was taken offline, goods could not be received there, and orders were cancelled or delayed while restoration ran longer than expected. This was an availability incident for the downstream businesses as well as a confidentiality one. Dutch trade reporting adds that CEVA isolated and took the affected systems offline, opened an external investigation and informed regulators (ICTMagazine.nl, 2026-08-10).

Two things are conspicuously absent and should stay that way in any internal write-up. No source identifies how CEVA's order-processing systems were reached — no vulnerability, no phishing, no credential theft, no malware family, no actor or extortion brand. And the provenance of data already circulating is disputed: Dutch reporting records that data taken from CEVA is being offered for sale on a criminal forum, while CEVA maintains that dataset is old data from an earlier 2025 breach (ICTMagazine.nl, 2026-08-10). Treating the material on offer as this incident's proceeds is therefore not supported, and neither is the converse — no independent party has adjudicated the dispute.

The incident involves two systems used for processing orders from one of bol's fulfilment centers. No bol systems were affected. However, data of customers whose orders were processed via this location may have been viewed or copied.

bol.com 2026-08-06

Mark Schenkel, a spokesperson for the Dutch data protection authority, told TechCrunch that the agency has received data breach reports from 10 organizations in relation to the incident.

such as if the company knows how much personal data was taken, or if Ceva has received any communication from the hackers, such as a ransom demand

TechCrunch 2026-08-10
incident11 Aug 04:50Zmulti-sourceOpen finding ↗