Estimated reading time: 3 minutes
A cyberattack on CEVA Logistics has disrupted operations at eight European warehouses, exposing customer data and delaying e-commerce shipments as retailers suspend connections to affected logistics systems.
The intrusion affected part of CEVA’s contract logistics network, according to reports published after customers were notified on August 1. The impact appears contained to the eight warehouses, while CEVA’s air, ocean, road, and rail transport management operations have continued normally.
The incident, which had been reported by Dutch NU.nl, and FreightWaves, has nevertheless exposed a critical vulnerability for retailers that depend on outsourced warehouse technology. bol, De Bijenkorf, and other customers have warned consumers that personal or order information may have been accessed, while fulfilment delays and cancellations have followed at some affected operations.
Retail orders disrupted as data exchanges are suspended
Bol said unauthorized parties gained access to two systems used to process orders at one of its distribution centres. The retailer said its own systems were not compromised but customer information processed through the location may have been accessed or copied.
As a precaution, bol suspended data exchanges with its logistics partner and temporarily removed products stored at affected locations from sale. Some orders have been cancelled, while others face delays. Returns and refunds may also take longer to process.
De Bijenkorf separately warned customers that processing of orders, returns, and refunds could take longer than normal. Its physical stores remain open and online ordering remains available.
The incident has also widened beyond the two Dutch retailers. Customers purchasing Steam hardware in Europe were warned on Monday that information associated with purchases may have been compromised. Reported information includes names, addresses, telephone numbers, email addresses, and details about products ordered and their prices.
There has been no indication that payment credentials were exposed in the bol incident.
Some applications and services at affected CEVA distribution centres have since been restored for certain customers, according to a source familiar with the investigation.
Investigation focuses on scope of CEVA breach
The Dutch Data Protection Authority and other authorities are investigating the incident, according to FreightWaves. CEVA has more than 1,000 warehouses worldwide, making the apparent containment of the intrusion to eight European facilities significant for customers using its wider network.
The disruption demonstrates how warehouse IT has become an operational dependency for modern supply chains. Distribution centres increasingly rely on connected systems to manage inventory, release orders, generate shipping information, and exchange data with retailers and carriers.
A cyber incident can therefore move rapidly from an information security problem to a physical logistics disruption, particularly in high-volume e-commerce operations where automated systems determine which products can be sold and dispatched.
CMA CGM’s 2020 attack offers earlier warning
CEVA’s parent group CMA CGM experienced a separate major cyberattack in September 2020, when malware targeted peripheral servers and forced the container shipping group to temporarily restrict external access to IT applications.
CEVA Logistics was explicitly excluded from that earlier incident. CMA CGM gradually restored access while keeping its maritime and port operations functioning and later said it suspected that the attack had resulted in a data breach.
The latest CEVA incident comes as logistics groups continue to strengthen cyber resilience across increasingly interconnected warehouse, transport, and customer platforms. Investigators have yet to publicly establish the full volume of data compromised in the current attack or identify the attackers.
CEVA’s recovery progress and the timetable for customers to safely reconnect their systems will determine how quickly remaining fulfilment delays can be cleared.
DISCLAIMER: “Breakbulk.News publishes editorial content, including news, features and press releases supplied by third‑party companies, institutions and PR agencies. Third parties who submit material to us are solely responsible for ensuring that all text, images, logos and other content they provide are accurate and that they hold all necessary rights, licences and permissions for news use. By submitting content to Breakbulk.News, contributors represent and warrant that their material does not infringe the rights (including copyright and related rights) of any third party and agree to indemnify Breakbulk.News respecting any claims arising from their submissions. human-edited, AI-assist. If you believe any content on our site infringes your rights, please contact us at info@breakbulk.news with full details and we will investigate promptly. Breakbulk.News is a Trademark of Breakbulk News & Media B.V. in The Netherlands.”




