Published Security3 min read
A 3PL Gets Breached and the Notification Letters Go Out on Its Clients' Letterhead
CEVA Logistics lost shipping at eight European warehouses on July 29 and customer data belonging to Valve, Ajax and De Bijenkorf went with it. The Dutch retailer is the one filing with the regulator.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- CEVA Logistics suffered a cyberattack on July 29 that disrupted parts of its European operations.
- The incident affected eight warehouses and halted shipments at those facilities.
- CEVA Logistics is still working to restore impacted services.
- CEVA Logistics operates in more than 170 countries and is part of the CMA CGM Group, one of the world's largest shipping and logistics companies.
- On August 1, CEVA notified affected customers that goods stored at the disrupted facilities could not be shipped.
Compiled by The WatchSomething wrong?How this is made
Why it matters
CEVA Logistics was hit by a cyberattack on July 29 that disrupted parts of its European operations and stopped shipments at eight warehouses, and the company says it is still working to restore affected services [1][2][3]. The operational damage is CEVA's; the data exposure is showing up on its customers' books, with Dutch department store chain De Bijenkorf notifying shoppers and filing a report with the Dutch Data Protection Authority over an incident that happened inside someone else's systems [11][18].
CEVA operates in more than 170 countries and is part of the CMA CGM Group, one of the largest shipping and logistics companies in the world [4]. On August 1, three days after the intrusion, it told affected customers that goods sitting in the disrupted facilities could not be shipped [5][6]. The company has not disclosed technical details or named a suspected threat actor, and no ransomware group has claimed responsibility [7].
The Register reported that the attack exposed customer data tied to major CEVA clients including the gaming platform Valve and the Dutch retailer Ajax [8]. Valve said payment details, passwords and Steam Guard codes were not exposed, for the straightforward reason that CEVA does not hold them, but warned users that what was taken could be used to build convincing impersonations of trusted services [9][10]. That is the standard shape of a third-party logistics breach: the crown jewels stay put, and what leaks is the connective tissue between a customer and a brand, which is exactly what a phishing operator needs.
De Bijenkorf's disclosure is the more useful document. It said names, contact details including email addresses, postal addresses and telephone numbers, and online order data may be involved, the latter covering products, prices, discounts, delivery information and a description of the payment method used [11][12]. No financial data was affected, and the retailer confirmed no payment details, IBANs, credit card numbers, usernames or passwords were in scope [11][17]. For business customers, company names and VAT numbers may also be involved where those were entered in My Account, and De Bijenkorf flagged that severely outdated VAT numbers belonging to freelancers and sole proprietorships can be composed of a citizen service number [13][14]. That last line is the one worth reading twice: a shipping label field quietly carrying a national identifier.
The retailer's own account of the event is short and points elsewhere. "A security incident has occurred at a logistics partner of de Bijenkorf. Unauthorized persons gained access to part of their systems. Our logistics partner intervened immediately, blocked access, and took additional security measures," it said [15]. Meanwhile De Bijenkorf carries the consequences: order processing, returns and refunds may run slow, though stores stay open and online orders can still be placed [16]. It notified customers as a precaution, engaged an external party to investigate cause and scope, and told anyone not yet contacted that they cannot be ruled out as affected while that work continues [18][19].
At least three named client organisations are now visible in this incident [21]. SecurityAffairs adds one loose thread without clearly attributing it to a company: in November, a hacker reportedly offered "the company's database" for sale on a dark web marketplace, claiming it contained customer lists, shipping records, contracts, pricing information and banking details [20].
What to watch: whether more CEVA clients surface with their own notifications, since the full scope of the exposure remains unclear with investigations running at both CEVA and its customers [22]; whether any actor claims the intrusion, which would tell you whether this was extortion or quiet theft [7]; and whether the Dutch DPA treats the citizen service number angle as a separate matter from ordinary contact-data loss [14][18]. For anyone with goods in a 3PL, the practical question is who drafts and signs the breach notice when the breach is not yours, and whether your contract says so.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
CEVA Logistics suffered a cyberattack on July 29 that disrupted parts of its European operations.
ReportedView cited source - [2]
The incident affected eight warehouses and halted shipments at those facilities.
ReportedView cited source - [4]
CEVA Logistics operates in more than 170 countries and is part of the CMA CGM Group, one of the world's largest shipping and logistics companies.
ReportedView cited source - [5]
On August 1, CEVA notified affected customers that goods stored at the disrupted facilities could not be shipped.
ReportedView cited source - [7]
CEVA did not disclose technical details about the attack or name the threat actor behind it, and no ransomware group has claimed responsibility.
ReportedView cited source
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityaffairs.comPierluigi PaganiniAug 12CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments
- thecyberexpress.comAshish KhaitanAug 13CEVA Logistics Cyberattack Disrupts European Warehouses, Exposes Customer Data
Additional citations
- The Register, as reported by SecurityAffairs and The Cyber Express
- Valve
- De Bijenkorf



