One compromised contract-logistics processor put ten organisations into breach notification at once — CEVA Logistics, eight European warehouses, and a bank, a retailer and a games platform all learning from their supplier
CEVA Logistics — a contract-logistics operator that has been part of the French shipping group CMA CGM since 2019 (ICTMagazine.nl, 2026-08-10) — confirmed to affected customers on 1 August 2026 that a cyber intrusion was affecting part of its European contract-logistics operations, telling TechCrunch that its security teams activated protocols and opened an investigation that is still running, and that the operational impact was limited to eight warehouses, with no other CEVA systems globally affected (TechCrunch, 2026-08-10). That is the whole of what the compromised party has said publicly. Dutch trade reporting records that CEVA itself has given no public reaction of its own to these incidents (ICTMagazine.nl, 2026-08-10), and its spokesperson declined to answer whether the company knows how much personal data was taken or whether it has heard from the intruders at all, including on a ransom demand (TechCrunch, 2026-08-10).
The reason this is an entry rather than one more breach is arithmetic. CEVA processes fulfilment and shipping data for many unrelated clients, so one intrusion at one processor created independent notification duties at each of them simultaneously: the Dutch data-protection authority's spokesperson confirmed to TechCrunch that it has received breach reports from ten organisations in relation to this single incident. The named downstream parties span sectors that share nothing but a logistics contract — ING in banking, bol.com and De Bijenkorf in retail, the football club AFC Ajax, the eyewear retailer Ace & Tate, and Valve, which told customers it learned on 7 August that data was taken from CEVA's systems and alerted customers who had recently bought its Steam hardware, noting CEVA holds their shipping and delivery information for 90 days after an order (TechCrunch, 2026-08-10); Dutch trade reporting scopes those Steam buyers to Europe (ICTMagazine.nl, 2026-08-10).
bol.com's own notice is the most specific account any party has published. It records that it was informed on 1 August, that the incident involves two systems used for processing orders from one of its fulfilment centres, that no bol systems were affected, and that data of customers whose orders were processed via that location may have been viewed or copied (bol.com, 2026-08-06). It also records the containment sequence — the logistics partner moved to stop the unauthorised access and brought in external specialists, and bol proactively halted data exchange with it pending assurance that resuming is safe — and the part that is easy to miss in a data-breach framing: the affected location's stock was taken offline, goods could not be received there, and orders were cancelled or delayed while restoration ran longer than expected. This was an availability incident for the downstream businesses as well as a confidentiality one. Dutch trade reporting adds that CEVA isolated and took the affected systems offline, opened an external investigation and informed regulators (ICTMagazine.nl, 2026-08-10).
Two things are conspicuously absent and should stay that way in any internal write-up. No source identifies how CEVA's order-processing systems were reached — no vulnerability, no phishing, no credential theft, no malware family, no actor or extortion brand. And the provenance of data already circulating is disputed: Dutch reporting records that data taken from CEVA is being offered for sale on a criminal forum, while CEVA maintains that dataset is old data from an earlier 2025 breach (ICTMagazine.nl, 2026-08-10). Treating the material on offer as this incident's proceeds is therefore not supported, and neither is the converse — no independent party has adjudicated the dispute.
The incident involves two systems used for processing orders from one of bol's fulfilment centers. No bol systems were affected. However, data of customers whose orders were processed via this location may have been viewed or copied.
Mark Schenkel, a spokesperson for the Dutch data protection authority, told TechCrunch that the agency has received data breach reports from 10 organizations in relation to the incident.
such as if the company knows how much personal data was taken, or if Ceva has received any communication from the hackers, such as a ransom demand
ATT&CK mapping
1 technique mapped from the cited reporting · MITRE ATT&CK v19.2
Collection TA0009
T1005Data from Local System
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.