Published Security3 min read
Retailers, not CEVA, are telling customers their shipment data was taken
CEVA Logistics has issued no statement and filed no regulatory report. What customers know is coming from the shops that shipped their parcels.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- CEVA Logistics, one of the biggest shipping and logistics companies in the world, suffered a major cyberattack, the effects of which are trickling down to many of its clients.
- The details of the hack are not yet publicly available, and what little information is out there came from the affected clients themselves.
- CEVA has not yet issued an official statement or filed a report with regulators.
- CEVA confirmed to TechCrunch that the attack most likely started on July 29, 2026 and affected at least eight warehouses across Europe.
- CEVA is a fully owned subsidiary of the CMA CGM group, the world's third-largest shipping company.
Compiled by The WatchSomething wrong?How this is made
Why it matters
CEVA Logistics, one of the largest shipping and logistics companies in the world, has been hit by a cyberattack whose consequences are landing on its clients rather than on CEVA itself [1]. The company has not published an official statement and has not filed a report with regulators, so nearly everything known publicly has come from the affected clients [2][3].
The shape of the incident, as reported in the Paul's Security Weekly segment published by SC World: CEVA confirmed to TechCrunch that the attack most likely began on July 29, 2026 and touched at least eight warehouses across Europe [4]. No group has claimed responsibility [8]. The stolen data covers shipments from May through July and includes name, address, phone number, email address and the item purchased [9].
That last field is the part worth sitting with. A parcel record is not a password dump, but name plus address plus phone plus what you bought is close to a script for a convincing follow-up call about a delivery problem, which is why the SC World analysis flags targeted social engineering and scam risk for anyone affected [11]. The people at risk never chose CEVA. They chose a retailer, and the retailer chose a fulfilment partner.
Which is what makes this a clean case study in how third-party breach notification actually works. CEVA notified retailers, and the retailers are notifying their own customers [7]. The breached party controls the facts and the timeline; the downstream brands own the customer conversation, the reputational cost and, in most jurisdictions, the legal duty to tell people. If the upstream provider stays quiet with regulators and the press, its clients are left explaining an incident whose scope they cannot independently verify [2][3].
Scale matters here, and so does what CEVA did right. CEVA is a wholly owned subsidiary of the CMA CGM group, the world's third-largest shipping company, and it operates 1,000 warehouses and handled 15 million shipments last year [5][6]. Eight confirmed warehouses is roughly 0.8 percent of that footprint [12], though facility count is a poor proxy for how many records moved. For orientation only: 15 million shipments a year averages about 1.25 million a month, so a three-month window is on the order of 3.75 million shipments network-wide, which is not an estimate of what was taken [13]. On the defensive side, the SC World analysis notes CEVA has a data retention policy and collects only the information needed to deliver a shipment, describing that as best practice for third-party integration [10]. Minimisation is why the loss is names and parcels rather than payment data.
What to watch: whether CEVA files with European regulators and whether a stated start date of July 29 can be reconciled with data reaching back to May, since that gap is either retention working as designed or dwell time nobody has measured yet [4][9][10]. Watch, too, for a claim of credit, which would tell you whether this was extortion or quiet collection [8]. And if you are a retailer with a logistics integration, the operational question is not whether your provider is secure. It is whether your contract obliges them to give you facts fast enough to notify on your own deadline.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
CEVA Logistics, one of the biggest shipping and logistics companies in the world, suffered a major cyberattack, the effects of which are trickling down to many of its clients.
- [2]
The details of the hack are not yet publicly available, and what little information is out there came from the affected clients themselves.
- [3]
CEVA has not yet issued an official statement or filed a report with regulators.
- [4]
CEVA confirmed to TechCrunch that the attack most likely started on July 29, 2026 and affected at least eight warehouses across Europe.
- [5]
CEVA is a fully owned subsidiary of the CMA CGM group, the world's third-largest shipping company.
- [6]
CEVA operates 1,000 warehouses and handled 15 million shipments last year.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- scworld.comLee NeelyAug 13The Breached WiFi AI Ports... What? - PSW #939
Additional citations
- SC World, Paul's Security Weekly #939 segment
- CEVA, as confirmed to TechCrunch and reported by SC World
- Lee's Take, SC World Paul's Security Weekly #939 segment



