Ajax, ING and Ace & Tate Also Hit by the CEVA Logistics Data Breach
One shared delivery partner has become a single weak point for many well-known brands; experts warn criminals can now combine data from different leaks to make scam messages more convincing.
See more of Dutch Brief in your Google search results
The data breach at the logistics company CEVA Logistics, which came to light earlier this week when the online store Bol and the department store de Bijenkorf warned their customers, has widened considerably. Several more well-known names have now said they are affected, including the football club Ajax, the bank ING and the eyewear chain Ace & Tate.
One weak link, many brands
The common thread is CEVA Logistics, an international logistics firm that handles warehousing and deliveries for all of these companies, and which therefore had access to the customer data needed to fulfil orders. The breach was not at the affected companies’ own systems, but at their shared delivery partner, which is why a single security incident has ended up touching so many different organisations at once.
CEVA has said it cannot rule out that personal data was leaked. The companies involved stress that, as far as they know, no payment details, bank information, usernames or passwords were taken. What may have been exposed is contact and order information: names, addresses, email addresses and phone numbers. For business customers of some firms, company names and VAT numbers may also be involved, and older Dutch VAT numbers can in some cases contain a citizen service number (BSN). According to RTL Nieuws, data belonging to Bol and de Bijenkorf customers is already being offered on the dark web.
Who is affected, and how
The details vary from company to company. At ING, the breach concerns customers who ordered physical products through the bank’s loyalty points shop, rather than banking data. Ace & Tate said an unauthorised party gained access, on 1 August, to part of the systems used for packing and shipping its orders, and warned that eyeglass prescriptions, financial data, usernames and passwords were not affected. Ajax is still investigating whether personal data was actually taken, and says address, order and contact details of supporters could be involved.
The reach extends beyond the Netherlands. The German online retailer Zalando has confirmed it also experienced the CEVA incident, though it says its own customers’ data was not affected, and CEVA has reported that several of its European warehouse locations are experiencing disruption.
SPONSORED
You’re overpaying your accountant. And they still don’t call you back.
Neno gives you a dedicated bookkeeper, automated admin, real-time financial insights and a free business bank account. Everything your business needs, in one place.
No chasing. No surprises. No unnecessary costs.
Delays and warnings
As with the earlier cases, there are practical knock-on effects. Ace & Tate and Ajax have both warned that orders and returns may take longer because of the logistics problems, while online ordering continues. The affected companies have reported the breach to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), as Bol and de Bijenkorf did earlier in the week, and Ajax has advised its supporters to be extra alert to phishing messages in the coming weeks. CEVA Logistics itself had not issued a public response at the time of writing, saying it would react at a later stage.
Why the bigger picture matters
Security experts say the widening list of victims points to a broader risk. When many separate breaches happen in a short space of time, criminals can combine the data from different leaks, matching a name from one with an email address or order history from another, to build a fuller picture of a person and make their scams far more convincing.
That is what makes the main piece of advice more important than usual. Because criminals may hold genuine details of people’s names, addresses and recent orders, the biggest danger now is targeted phishing: fake messages, by email, text or phone, that look believable precisely because they refer to a real purchase or account. The sensible response is to treat any unexpected message about an order, delivery, refund or payment with caution, even if it quotes accurate details, and not to click on links or call phone numbers contained in such messages. To check on an order, go to the company’s own website or app directly rather than following a link. Anyone who thinks they have been targeted can report it to the Fraud Helpdesk.
For most people there is no need to panic, particularly as passwords and payment data appear not to have been taken. But this is a good moment to be a little more sceptical than usual about messages landing in your inbox.




