Cyberattack Disrupts Eight Ceva Logistics Warehouses in Europe, Affecting Retailers
Key Takeaways
- ā¢A cyberattack compromised eight Ceva Logistics warehouses in Europe, disrupting warehouse operations and causing shipping delays for numerous retail customers.
- ā¢The Dutch Data Protection Authority is investigating the breach, which could trigger GDPR fines of up to 4% of Ceva's global annual revenue if EU residents' personal data was involved.
- ā¢Dutch retailers De Bijenkorf and bol notified customers that some personal data may have been accessed or copied, though credit card and payment details were not affected.
- ā¢Ceva's air, ocean, ground, and rail transportation management operations were not impacted, as the attack was confined to the eight warehouse facilities.
- ā¢Partial recovery has begun at certain distribution centers, with some applications and services already restored for specific customers.

A cyberattack over the weekend disrupted operations at eight Ceva Logistics warehouses in Europe, triggering shipping delays for numerous retail customers that store inventory at those facilities, according to a source close to the situation.
Affected customers were notified on Aug. 1 that a cyber intrusion had compromised part of Ceva's contract logistics operation, the source told FreightWaves. Ceva Logistics has not publicly commented on the breach, which is under investigation by the Dutch Data Protection Authority, other law enforcement agencies, and the companies involved. The involvement of the Dutch regulator signals potential implications under Europe's General Data Protection Regulation, which empowers authorities to levy fines of up to 4% of a company's global annual revenue for data breaches involving EU residents' personal information.
Ceva, a subsidiary of French shipping giant CMA CGM, ranks among the world's largest third-party logistics providers, operating more than 1,000 warehouses globally and generating $18.3 billion in revenue last year. According to the source, who is familiar with the investigation, no Ceva systems beyond the eight warehouses were affected. Air, ocean, ground, and rail transportation management activities continue to operate without incident.
The severity of the disruption varied by customer, depending on how reliant each was on the applications and services running at the eight impacted warehouses. The incident underscores a structural risk in modern e-commerce supply chains: when multiple retailers consolidate inventory and order processing through a single third-party logistics provider, a compromise at that vendor can cascade across many consumer-facing businesses simultaneously.
Retailers Warn Customers of Data Exposure
De Bijenkorf, a Dutch retail chain with both physical stores and an online shop, and e-commerce retailer bol both posted public alerts on Wednesday informing customers that hackers had compromised the IT systems of a logistics vendor. The companies said some private customer data may have been exposed, though credit card and payment details were not affected.
In a statement on its website, bol said: "The partner's investigation has shown that unauthorized parties gained access to some of its systems and data. The incident involves two systems used to process orders from one of bol's distribution centres. No bol systems were affected. However, customer data processed through this location may have been accessed or copied."
"Upon discovering the incident, the warehousing partner immediately took measures to stop the unauthorized access and engaged external cybersecurity specialists to conduct a further investigation. As a precaution, bol immediately suspended all data exchanges with this partner. These will only resume once it has been confirmed that this can be done safely," the company added.
Bol reported that its own products and those of its selling partners stored at the affected locations have been temporarily taken offline. Some orders have been canceled or may experience delays. All other bol logistics locations remain fully operational.
De Bijenkorf issued its own message to customers: "The processing of orders, returns, and refunds may take longer than customers are used to. Our stores remain open and online orders can be placed."
Partial Recovery Underway
Some applications and services at the distribution centers have already been restored for certain customers, the source said.
The freight transportation sector has been a recurring target of cyber and ransomware attacks. Shipping giant Maersk and Seattle-based Expeditors International both suffered major attacks in previous years, and Estes Forwarding Worldwide was hit by a cyberattack last summer. The 2017 NotPetya attack on Maersk alone cost the company an estimated $300 million, illustrating the outsized financial impact such incidents can have on logistics operators that manage global flows of goods.