CEVA cyberattack disrupts eight European warehouses

CEVA cyberattack disrupts eight European warehouses

CEVA’s European warehouse cyberattack disrupted operations and exposed customer data. Eight warehouses were affected, while customer disclosures show the incident also reached delivery and order information held inside outsourced fulfilment systems.


IN Brief:

  • Eight CEVA contract logistics warehouses in Europe were disrupted following a cyberattack that began on 29 July.
  • Customers including bol, De Bijenkorf, and Valve have reported potential exposure of order or delivery-related personal information.
  • The incident shows how outsourced fulfilment can combine physical service disruption with third-party data exposure.

CEVA Logistics is continuing to recover from a cyberattack that disrupted operations at eight European contract logistics warehouses and exposed information held on behalf of several customers.

The disruption began on 29 July, with affected customers notified from 1 August that systems supporting warehouse operations had been compromised. Goods held at the affected facilities were delayed, while subsequent disclosures from CEVA customers showed that the incident also reached data used to process orders and deliveries.

The two consequences are closely connected. Modern contract logistics warehouses depend on warehouse management, order processing, inventory, carrier, customer, and transport systems to release stock into the physical network. A building can retain its labour, racking, vehicles, and inventory while being unable to fulfil orders at normal speed because the digital instructions governing those assets are unavailable or cannot be trusted.

Dutch online retailer bol said two systems used for order processing at one fulfilment centre were involved. The retailer said its own systems were not affected, but information belonging to customers whose orders had passed through the CEVA location may have been viewed or copied. The operational impact also prevented some stock at the location from being sold or replenished while recovery continued.

De Bijenkorf separately warned that information including names, addresses, email addresses, telephone numbers, and online order details could have been affected. The retailer said payment information, bank account numbers, credit card details, usernames, and passwords were not involved.

Valve also notified European customers who had bought physical Steam hardware. CEVA receives delivery-related information to fulfil those orders, and Valve said details potentially affected included names, addresses, contact information, and information about the products ordered. The gaming company said unrelated account and payment credentials were not provided to the logistics operator.

The disclosures illustrate the quantity of commercial information that can accumulate inside an outsourced fulfilment operation. Warehouses need more than a delivery address to function efficiently: order references, product details, customer contact information, returns data, and shipment history may all remain available after dispatch to support customer service and reverse logistics.

That makes cyber resilience part of the physical supply chain rather than a separate IT concern. A manufacturer or retailer outsourcing fulfilment also becomes dependent on the systems used by its 3PL to hold inventory records, release orders, schedule despatches, and exchange data with carriers. If those systems stop, stock that is physically available may still be commercially inaccessible.

The consequences vary according to network design. A customer holding inventory across several warehouses may be able to redirect orders or replenish from another location, albeit at additional cost. A business whose European stock is concentrated in a single outsourced facility has far less room to manoeuvre when that warehouse loses its normal operating systems.

Data retention creates another dependency. Logistics providers may need historic delivery information for returns, claims, service enquiries, or warranty processes, meaning customer data can remain in the fulfilment environment after the original parcel has arrived. The longer those records are retained, the more important clear retention, access, and segregation controls become.

The recovery process also has to protect inventory accuracy. Manual workarounds can keep limited cargo moving, but a warehouse designed around digital picking, scanning, stock allocation, and despatch controls cannot simply revert to paper indefinitely without increasing the risk of incorrect stock records or misrouted orders.

CEVA operates more than 1,700 facilities worldwide across contract logistics and transport activities. The current incident has been reported as affecting eight European warehouses, but the number of unrelated customers caught in those locations demonstrates how concentrated operational dependencies can spread one disruption across several supply chains.

The technical method used to compromise CEVA’s systems has not been publicly established, and the total number of people whose information may have been exposed remains unclear. That makes speculation about the attackers or intrusion method premature. The confirmed operational facts are already substantial enough: warehouse activity was disrupted, shipments were delayed, and customer information held for fulfilment purposes may have been accessed.

For businesses reviewing outsourced logistics contracts, those facts shift cyber questions closer to conventional continuity planning. Alternative stock locations, recovery procedures, system segregation, data retention, and the ability to keep a limited flow of goods moving during an IT shutdown can be as important as normal warehouse throughput.

The eight affected CEVA locations will eventually return to routine operation. The more durable consequence may be the reminder that contract logistics increasingly outsources systems and data dependencies alongside warehouse space and labour — dependencies that only become visible when the screens stop working and the stock stops moving with them.


Stories for you


  • Davies Turner opens Arctic China-UK container route

    Davies Turner opens Arctic China-UK container route

    Davies Turner has launched a seasonal Arctic China-UK container service. The eight-week programme uses Sea Legend sailings from Ningbo to Felixstowe with a stated 21-day ocean transit.


  • CEVA cyberattack disrupts eight European warehouses

    CEVA cyberattack disrupts eight European warehouses

    CEVA’s European warehouse cyberattack disrupted operations and exposed customer data. Eight warehouses were affected, while customer disclosures show the incident also reached delivery and order information held inside outsourced fulfilment systems.