
CEVA Logistics confirmed a cyberattack that began on 29 July and disrupted operations at eight warehouses across Europe, halting shipments and triggering a potential data breach affecting customer personal information.
The company notified customers on 1 August of the delays, stating that the incident has not been linked to any known ransomware group and that its other global systems remain secure. Exposed data includes names, contact details and order information for clients such as De Bijenkorf, Valve, Bol and Ajax, although financial records were not compromised.
Security researchers note that the attackers allegedly offered CEVA’s compromised database for sale on dark web forums, raising concerns about further misuse of the stolen supply chain data. No specific vulnerability or CVE identifier has been published in connection with the breach, suggesting the intrusion may have relied on compromised credentials or phishing rather than a software flaw.
The incident fits a growing pattern of threat actors targeting logistics firms because of their pivotal role in global supply chains and the valuable data they handle. Experts warn that the leaked information could fuel targeted phishing campaigns against CEVA’s partners and customers in the coming weeks.
Defenders should review access logs for unusual authentication attempts, enforce multi‑factor authentication on all remote connections and segment warehouse management systems from corporate networks to limit lateral movement. Monitoring dark web marketplaces for mentions of CEVA data and promptly resetting any compromised credentials are also prudent steps.
Organisations that rely on CEVA’s services are advised to reassess their own incident response plans, communicate transparently with affected customers and consider additional encryption for sensitive data shared with third‑party logistics providers.