CEVA Logistics 2026: ransomware paralyzes 8 European warehouses and exposes major clients' data
> In short: Between July 29 and August 1, 2026, CEVA Logistics — a subsidiary of French shipping group CMA CGM — suffered a ransomware attack that paralyzed eight European warehouses, including one in the Netherlands. Air, ocean, ground, and rail transportation services kept running, but warehousing and contract logistics operations were hit hard: delays, blocked orders, cancellations. Data belonging to major clients — Valve (Steam hardware), Bol.com, ING, Ajax Amsterdam, De Bijenkorf, Ace & Tate — was exfiltrated: names, addresses, phone numbers, emails, order details, and VAT numbers. No payment card data or passwords were reportedly compromised. A class-action lawsuit was filed in the US, alleging the company prioritized cost-cutting over cybersecurity.
An attack emblematic of third-party logistics risk
CEVA Logistics is no minor player: it's one of the largest contract logistics providers in the world, owned by CMA CGM, itself a major global shipping group. Its clients aren't small operations either: Valve, a bank (ING), a professional football club, several retail chains. In other words, the incident illustrates a pattern that keeps recurring — the attack doesn't target the consumer-facing brand directly, but one of its logistics or technical vendors, whose compromise cascades into exposing data from dozens of clients who made no security mistake of their own.
What was exfiltrated, and what sets this incident apart
The ransomware locked the IT systems of eight warehouses, causing order delays and cancellations publicly documented by several affected clients. Beyond the operational disruption, a data exfiltration hit end-customer order information: contact details, purchase history, corporate VAT numbers. A separate lawsuit, filed on behalf of CEVA employees, also alleges exposure of social security numbers and internal bank account details — suggesting the compromise went beyond warehousing systems and reached HR data as well.
The ransomware group CoinbaseCartel is named in at least one of the ongoing legal proceedings, with no official confirmation yet of the initial attack vector.
The lesson for companies that depend on a logistics or technical vendor
This incident is a reminder of an often underestimated reality: the security of your customer data also depends on that of your subcontractors, a dependency largely outside your direct control. A few concrete levers to reduce this risk:
An audit shouldn't stop at your direct technical perimeter: it should also question the subcontracting chain and the data flows leaving it, particularly for HR and payroll SaaS platforms that pass sensitive data to outsourced payroll, archiving, or document logistics providers.
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
Oracle E-Business Suite CVE-2025-61882: Cl0p hits Michelin and 100+ companies in MOVEit's wake
The Cl0p group exploited a critical zero-day in Oracle E-Business Suite (CVE-2025-61882, CVSS 9.8) to run a mass data-extortion campaign. Michelin, Harvard, the Washington Post, Logitech, Cox Enterprises and more than 100 organizations worldwide were hit.
MOVEit 2023: How Cl0p Exploited a Zero-Day to Hit 2,500+ Companies
Technical analysis of the Cl0p campaign against MOVEit Transfer in 2023: the SQLi vulnerability, exploitation chain, and lessons.
Brevo Hacked: Trezor Phishing Sent from help@trezor.io, 347,000 Emails Targeted
On September 9, 2026, an unauthorized actor accessed French email platform Brevo (formerly Sendinblue), compromising 120 customer accounts including Trezor's. Fake security alerts went out from the genuine help@trezor.io address to 347,000 subscribers; 2,500 people clicked the malicious link before the domain was taken down in 20 minutes.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.