A CEVA Logistics cyberattack disrupted parts of the company’s European operations on July 29, halting shipments at eight affected warehouses and exposing customer data tied to several major clients. CEVA Logistics, which operates in more than 170 countries, is part of the CMA CGM Group, one of the world’s largest shipping and logistics conglomerates.
On August 1, CEVA notified affected customers that goods stored at the disrupted facilities could not be shipped, underscoring how the CEVA Logistics cyberattack directly hit supply chain and logistics operations tied to the CMA CGM Group network.
The company has not disclosed technical details about the intrusion or named a suspected threat actor. No ransomware group has claimed responsibility for the incident so far.
What Data Was Exposed During the CEVA Logistics Cyberattack?
The breach exposed customer data connected to major CEVA clients, including gaming platform Valve and Dutch retailer Ajax. Valve stated that payment details, passwords, and Steam Guard codes were not compromised, as CEVA does not have access to that information.
The company nonetheless cautioned that the exposed data could be leveraged by cybercriminals to build convincing phishing campaigns, and it urged users to remain alert to suspicious emails or messages attempting to impersonate trusted services.
De Bijenkorf Confirms Data Exposure
Dutch premium department store chain De Bijenkorf, also affected by the CEVA Logistics cyberattack, said the breach may have exposed customer names, addresses, email addresses, phone numbers, and online order details. The retailer confirmed that no financial data was compromised.
In a statement, De Bijenkorf said the data potentially involved includes contact details such as email addresses, addresses, and telephone numbers, along with data regarding online orders such as products, prices, discounts, delivery information, and payment method descriptions.
The company added that for business customers, company names and VAT numbers may also be affected if entered in their account, and that severely outdated VAT numbers for freelancers and sole proprietors may be composed of a citizen service number.
De Bijenkorf attributed the breach to its logistics partner, stating: “A security incident has occurred at a logistics partner of de Bijenkorf. Unauthorized persons gained access to part of their systems. Our logistics partner intervened immediately, blocked access, and took additional security measures.”
The retailer said order processing, returns, and refunds may take longer than usual, though its stores remain open and online orders can still be placed. It confirmed that no payment details, IBANs, credit card numbers, usernames, or passwords were involved, and that it has notified customers as a precaution and filed a report with the Dutch Data Protection Authority. An external party is currently investigating the cause and scope of the incident.
De Bijenkorf said affected customers would be contacted directly via email from its official address, and that anyone not yet notified cannot be ruled out as impacted while the investigation continues.
The CEVA Logistics cyberattack highlights the exposure risk facing large logistics networks tied to global conglomerates like the CMA CGM Group, where a single breach at one facility can ripple across multiple retail and enterprise clients. With no threat actor identified and investigations ongoing at both CEVA and its affected customers, the full scope of the data exposure remains unclear.







































