CEVA Logistics and Bol: Bol also warns of a data breach at a logistics partner

CEVA Logistics and Bol: Bol also warns of a data breach at a logistics partner

Cyberattack on CEVA Logistics Exposes Bol Customer Data

A cyber incident targeting CEVA Logistics, a logistics and warehousing partner for Dutch online retailer Bol, has potentially exposed customer data. The breach was first flagged by De Bijenkorf, which had previously issued warnings about a similar incident involving the same company.

Bol confirmed that its own systems remained unaffected, but customer information including names, addresses, phone numbers, email addresses, and order details may have been accessed or stolen. Payment details and passwords were not compromised. Affected customers are being notified directly.

As a precaution, Bol temporarily took offline the product range of its sales partners linked to the affected site, leading to order cancellations and delays. CEVA Logistics also handles orders for other retailers, though it remains unclear whether their customers were impacted.

The incident highlights the risks of third-party supply chain vulnerabilities in logistics operations.

Source: https://www.retaildetail.eu/news/general/bol-also-warns-of-a-data-breach-at-a-logistics-partner/

CEVA Logistics TPRM report: https://www.rankiteo.com/company/ceva-logistics

Bol TPRM report: https://www.rankiteo.com/company/bollore-logistics

"id": "bolcev1786004807",
"linkid": "bollore-logistics, ceva-logistics",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Customers whose data was '
                                              'exposed (exact number not '
                                              'specified)',
                        'industry': 'E-commerce',
                        'location': 'Netherlands',
                        'name': 'Bol',
                        'type': 'Online Retailer'},
                       {'customers_affected': 'Potentially customers of other '
                                              'retailers using CEVA Logistics '
                                              '(unconfirmed)',
                        'industry': 'Logistics',
                        'name': 'CEVA Logistics',
                        'type': 'Logistics and Warehousing'}],
 'customer_advisories': 'Affected customers are being notified directly',
 'data_breach': {'data_exfiltration': 'Potentially (data may have been '
                                      'accessed or stolen)',
                 'personally_identifiable_information': 'Names, addresses, '
                                                        'phone numbers, email '
                                                        'addresses',
                 'sensitivity_of_data': 'High (PII exposed, but payment '
                                        'details and passwords were not '
                                        'compromised)',
                 'type_of_data_compromised': 'Personally Identifiable '
                                             'Information (PII), Order '
                                             'Details'},
 'description': 'A cyber incident targeting CEVA Logistics, a logistics and '
                'warehousing partner for Dutch online retailer Bol, has '
                'potentially exposed customer data. The breach was first '
                'flagged by De Bijenkorf, which had previously issued warnings '
                'about a similar incident involving the same company. Bol '
                'confirmed that its own systems remained unaffected, but '
                'customer information including names, addresses, phone '
                'numbers, email addresses, and order details may have been '
                'accessed or stolen. Payment details and passwords were not '
                'compromised. Affected customers are being notified directly. '
                'As a precaution, Bol temporarily took offline the product '
                'range of its sales partners linked to the affected site, '
                'leading to order cancellations and delays. CEVA Logistics '
                'also handles orders for other retailers, though it remains '
                'unclear whether their customers were impacted.',
 'impact': {'data_compromised': 'Customer data including names, addresses, '
                                'phone numbers, email addresses, and order '
                                'details',
            'identity_theft_risk': 'Potential risk due to exposure of '
                                   'personally identifiable information',
            'operational_impact': 'Order cancellations and delays due to '
                                  'temporary takedown of product range',
            'payment_information_risk': 'None (payment details and passwords '
                                        'were not compromised)',
            'systems_affected': 'CEVA Logistics systems (third-party logistics '
                                'partner)'},
 'lessons_learned': 'Highlights the risks of third-party supply chain '
                    'vulnerabilities in logistics operations',
 'references': [{'source': 'Incident description'}],
 'response': {'communication_strategy': 'Direct notifications to affected '
                                        'customers',
              'containment_measures': 'Temporary takedown of affected product '
                                      'range'},
 'title': 'Cyberattack on CEVA Logistics Exposes Bol Customer Data',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.