Back to The News Desk
Ceva Logistics — one shipping vendor, seven brands writing to their customers Logistics giant Ceva was breached in late July. ING, Ajax, Bol, De Bijenkorf, Ace & Tate, Valve, and Pokémon Center are all now writing to their customers. // THIRD-PARTY DESK   ·   24 AUG 2026 UNCLASSIFIED // PUBLIC SIG · b4d26c5b4e710e68 SOURCE · techcrunch.com Ceva Logistics — one shipping vendor… SUPPLY-CHAIN · FINANCIAL-SERVICES · COMMENTARY
// News Desk · 24 August 2026 · supply chain · financial services · commentary

Ceva Logistics — one shipping vendor, seven brands writing to their customers

Logistics giant Ceva was breached in late July. ING, Ajax, Bol, De Bijenkorf, Ace & Tate, Valve, and Pokémon Center are all now writing to their customers.

Ceva Logistics — a global shipping and fulfilment giant most people have never heard of — was breached between 29 July and 1 August 2026. The intruders reached Ceva’s servers and pulled customer records: names, physical addresses, phone numbers, email addresses, and order details. Ceva has not attributed the intrusion to a named group, and no leak-site listing has surfaced. The Dutch Data Protection Authority has, as of the current week, received breach notifications from ten separate downstream organisations tied to the same incident.

The named downstream victims, so far, are: ING, Ajax FC, Bol, De Bijenkorf, Ace & Tate, Valve (Steam), and Pokémon Center. The last of those was confirmed on 18 August, three weeks after the intrusion window closed. Retailers have paused shipments; Bol reported it could not receive stock from suppliers or ship items already in Ceva warehouses. The story is not over. Given the disclosure cadence — one to two new named victims per week — expect more names to surface between now and mid-September.

The interesting entry on that list, for a UK financial-services audience, is ING. A bank whose entire customer proposition rests on “your money is safe with us” is now writing to customers because a shipping vendor got hacked. From a regulatory perspective, that’s third-party risk crystallising exactly as regulators have been warning for two years. From a customer’s perspective, it’s “my bank leaked my address,” and no customer distinguishes between the bank and its outsourced fulfilment partner. The reputational cost lands on the brand the customer chose to trust, not the vendor they’ve never heard of.

The lesson defenders keep re-learning is that a third-party risk register is a customer-trust register in disguise. Every vendor with your customer data is one incident away from becoming the entity your customers blame you for. Perimeter thinking cannot fix this — the perimeter of the bank was not breached. What can be controlled is the data-flow perimeter around each integration: how much of your data any single vendor holds, how narrowly it flows through the trust boundary, how quickly containment can be proven when the vendor’s incident-response call comes in.

Ceva is not a novel attack. It is a very ordinary attack against a very ordinary vendor, whose knock-on effects have made it look extraordinary because so many brands share the same fulfilment layer. Save it as the reference case the next time someone in a risk conversation asks whether segmentation, data-minimisation across integrations, and blast-radius planning are worth the effort ahead of the next inevitable vendor incident.

Sources

Back to The News Desk