Back to blog
RansomwareSupply chainData breach

CEVA Logistics 2026: ransomware paralyzes 8 European warehouses and exposes major clients' data

Published on 2026-09-056 min readCleanIssue

> In short: Between July 29 and August 1, 2026, CEVA Logistics — a subsidiary of French shipping group CMA CGM — suffered a ransomware attack that paralyzed eight European warehouses, including one in the Netherlands. Air, ocean, ground, and rail transportation services kept running, but warehousing and contract logistics operations were hit hard: delays, blocked orders, cancellations. Data belonging to major clients — Valve (Steam hardware), Bol.com, ING, Ajax Amsterdam, De Bijenkorf, Ace & Tate — was exfiltrated: names, addresses, phone numbers, emails, order details, and VAT numbers. No payment card data or passwords were reportedly compromised. A class-action lawsuit was filed in the US, alleging the company prioritized cost-cutting over cybersecurity.

An attack emblematic of third-party logistics risk

CEVA Logistics is no minor player: it's one of the largest contract logistics providers in the world, owned by CMA CGM, itself a major global shipping group. Its clients aren't small operations either: Valve, a bank (ING), a professional football club, several retail chains. In other words, the incident illustrates a pattern that keeps recurring — the attack doesn't target the consumer-facing brand directly, but one of its logistics or technical vendors, whose compromise cascades into exposing data from dozens of clients who made no security mistake of their own.

What was exfiltrated, and what sets this incident apart

The ransomware locked the IT systems of eight warehouses, causing order delays and cancellations publicly documented by several affected clients. Beyond the operational disruption, a data exfiltration hit end-customer order information: contact details, purchase history, corporate VAT numbers. A separate lawsuit, filed on behalf of CEVA employees, also alleges exposure of social security numbers and internal bank account details — suggesting the compromise went beyond warehousing systems and reached HR data as well.

The ransomware group CoinbaseCartel is named in at least one of the ongoing legal proceedings, with no official confirmation yet of the initial attack vector.

The lesson for companies that depend on a logistics or technical vendor

This incident is a reminder of an often underestimated reality: the security of your customer data also depends on that of your subcontractors, a dependency largely outside your direct control. A few concrete levers to reduce this risk:

  • Map the data actually shared with each vendor — many companies only discover, after a third-party incident, the true scope of information transmitted through a simple logistics or technical integration.
  • Require contractual security and rapid-notification clauses in case of an incident at the vendor, with clear and enforceable deadlines.
  • Limit data transmitted to the strict minimum: does a logistics provider really need the full VAT number and detailed order history, or would an order ID suffice for the operational flow?
  • Plan crisis communication ahead of time: if a vendor is compromised, your customers will hold you accountable regardless of whether the flaw sits in your own systems.
  • An audit shouldn't stop at your direct technical perimeter: it should also question the subcontracting chain and the data flows leaving it, particularly for HR and payroll SaaS platforms that pass sensitive data to outsourced payroll, archiving, or document logistics providers.

    Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit