Summary
- A cyber intrusion has disrupted operations at eight CEVA Logistics warehouses in Europe, according to reporting on the investigation.
- Retailers including bol and De Bijenkorf have reported fulfilment delays and possible exposure of customer information.
- The incident shows how an attack on outsourced logistics can propagate into sales, customer service, and data exposure.
A cyberattack on CEVA Logistics has moved beyond the systems of one freight company and into the operations of businesses that depend on its European warehouses, disrupting retail fulfilment while exposing customer information held inside outsourced logistics processes.
Operations at eight CEVA warehouses in Europe were affected by the intrusion, according to reporting citing a source close to the investigation. Customers were informed on 1 August that part of CEVA’s contract-logistics operation had been compromised, while its air, ocean, road, and rail transport-management activities were reported to be continuing.
CEVA has not issued a public statement detailing the cause of the attack or the full scope of the affected data. Customer notifications, however, have begun to show how an intrusion into a logistics provider can propagate into businesses whose own networks were not breached.
Dutch ecommerce group bol said two systems used to process orders from one of its distribution centres had been accessed, potentially allowing customer information handled at that site to be viewed or copied. Bol suspended data exchanges with the logistics provider as a precaution and temporarily removed affected products from sale, while some orders were cancelled or delayed.
Department-store group De Bijenkorf has also warned of slower deliveries, returns, and refunds while the incident is investigated. Valve, meanwhile, has notified European customers who bought Steam hardware that delivery-related personal information held by CEVA was likely compromised, potentially including names, addresses, telephone numbers, and email addresses. Payment information, passwords, and Steam security codes were not held by the logistics provider.
The operational boundary of the incident is therefore considerably wider than the network where the attacker first gained access. Warehouse and order-processing systems connect inventory, customer records, carrier information, and retailer workflows, so taking part of that chain offline can remove products from sale, interrupt returns, delay refunds, and create a second problem through exposed personal data.
Logistics technology is a particularly unforgiving point of concentration because outsourcing warehousing and fulfilment gives retailers access to specialist infrastructure and economies of scale while also placing customer operations onto systems outside their direct control. When those systems fail, an organisation can be dealing with service disruption and customer notification even though its own environment remained secure.
Bol’s decision to halt data exchanges illustrates the resulting trade-off. Disconnecting systems can contain further exposure, but the same action removes part of the digital connection required to keep orders moving. Cyber containment and business continuity can therefore pull in opposite directions during the earliest stages of an incident.
The attack also shows why third-party risk cannot be reduced to a questionnaire completed when a supplier contract is signed. Logistics providers may retain names, addresses, contact details, order information, and delivery records because those datasets are necessary to provide the service. Once information leaves the retailer’s environment, security depends on how the supplier stores it, segregates customers, manages access, limits retention, and restores systems after an intrusion.
Data minimisation can reduce the eventual blast radius without removing the operational dependency. Valve’s customer notice is instructive: CEVA apparently did not hold Steam account credentials or payment information, limiting the sensitivity of the exposed dataset, but names, addresses, phone numbers, and email addresses still create material opportunities for convincing phishing and delivery scams.
Corporate resilience is difficult to measure when so much operational technology sits outside the company boundary. A business can maintain strong internal controls while relying on external organisations for fulfilment, software, payments, payroll, customer service, or infrastructure, leaving its practical resilience partly dependent on how those suppliers respond when their own systems fail.
CEVA operates more than 1,000 warehouses globally, according to reporting on the incident, so the apparent concentration of disruption within eight European sites is important. Yet the consequences emerging from that relatively limited footprint show how quickly an operational cyberattack can spread commercially without spreading technically.
The investigation still has to establish the attacker, entry point, complete data exposure, and recovery timeline. Affected customers are already dealing with the more immediate consequences: products that cannot move normally through fulfilment systems, personal information that may have been copied, and a supply chain that has become part of the cyber incident response.












