Large warehouse showing data breach disrupts operations

Data Breach Hits Global Logistics Giant Ceva and Disrupts Operations at Various Warehouses

A data breach at Ceva Logistics, a subsidiary of CMA CGM Group, has affected numerous companies and leaked their customers’ personal information.

The Marseille, France-headquartered logistics giant handles over 15 million orders from its over 1,000 warehouses and reported annual revenue of $18.3 billion in 2025.

Between July 29, 2026, and August 1, 2026, unauthorized third parties accessed Ceva servers and compromised personal information, according to data breach notifications sent by various companies to affected customers.

Ceva data breach leaks personal information

While the leaked information varied by individual, the breach included names, addresses, including street addresses, postal codes, cities, and countries, phone numbers, email addresses, and customer order details.

Valve, a Steam hardware distributor, has confirmed that the Ceva data breach leaked its customer data. Bol, a Utrecht, Netherlands-based online retailer, also announced that its customers’ personal information was illegally accessed by unauthorized individuals. It also warned that order shipments would be affected.

“On August 1, bol was informed about a cyber incident at the logistics warehousing partner we work with. The investigation shows that unauthorized individuals gained access to systems and data of this logistics warehousing partner,” it stated.

Bol said the system disruption also interfered with its ability to receive items from suppliers, and items already at affected warehouses could not be sold or shipped. Nevertheless, the company said shipments from unaffected warehouses continued without any interruptions.

Similarly, Amsterdam, Netherlands-based luxury retailer De Bijenkorf said the Ceva data breach compromised the personal information of its customers and disrupted operations, resulting in delays.

Other companies affected by the Ceva data breach include Ajax football club, prescription glasses and sunglasses maker Ace & Tate, and banking giant ING.

Meanwhile, Ceva was working to restore the affected systems to ensure its partners resume normal operations. According to the logistics company, the data breach affected only 8 European warehouses, while other global operations were unaffected.

Affected companies have advised their customers to be on the lookout for scam emails from cybercriminals trying to lure them into disclosing their personal information, like credit card details.

So far, Ceva has not attributed the data breach to any cyber extortion gang and has not disclosed how the attacker gained access to its systems. Similarly, there is no word on whether the attackers have demanded any ransom to avoid leaking the stolen information online. At the time of publication, the logistics company has also yet to disclose if the attacker deployed ransomware or the number of affected individuals.

Logistics companies targeted

Logistics companies are a lucrative target for cybercriminals due to the impact of supply chain disruption. Attackers also target them due to the valuable information they collect and store in the course of business.

“People often overlook logistics companies as cyber targets, but they sit at the center of thousands of transactions between businesses and their customers,” said Joseph Perry, Cybersecurity Researcher and Advanced Services Lead at Arcova. “That makes them an appealing target because a compromise can create operational problems while also giving attackers access to information about the people and products moving through the system.”

In early August 2026, Uber Freight disclosed a data breach that compromised the personal information of its clients. However, the data breach did not disrupt operations.

Similarly, a data breach at global shipping giant Hipshipper used by Amazon, eBay, and Shopify exposed 14 million records in 2025.

In 2022, Expeditors International shut down its systems after it became the victim of a targeted cyber attack. Two years earlier, a ransomware attack disrupted CMA CGM operations after shutting down the company’s website and mobile applications. A NotPetya cyber attack also affected global shipping giant A.P. Møller – Mærsk, shutting down some systems at various ports in 2017.

“The CEVA incident is a good reminder that most security programs end at your own walls, but your data does not. Most organizations have solid visibility into their own environment and very little, if at all, into how a vendor is accessing, storing, or protecting the data they handed over. That gap is why scoping these types of incidents are difficult,” concluded Christopher DeBrunner, CISO, CBTS.