Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
CEVA Logistics

CEVA Logistics Vendor Cyber Rating & Cyber Score

cevalogistics.com

CEVA provides world-class supply chain solutions for large and medium-size national and multinational companies across the globe. As an industry leader, CEVA offers customers complete supply chain design and implementation in contract logistics and freight management, alone or in combination. Together with CMA CGM, a leading worldwide shipping group and CEVA’s strategic partner, we are able to offer our customers end-to-end logistics solutions. CEVA’s integrated global network has over 1,000 facilities in more than 170 countries and 110,000 employees; all dedicated to delivering consistently excellent operations and supply chain solutions.


CEVA Logistics A.I CyberSecurity Scoring

CEVA Logistics
Company Information
Website:http://www.cevalogistics.com
Employees number:69,342
Number of followers:2,076,851
NAICS:47
Industry Type:Transportation, Logistics, Supply Chain and Storage
Homepage:cevalogistics.com
CEVA Logistics Risk Score (AI oriented)
Between 550 and 599
logo
CEVA LogisticsTransportation, Logistics, Supply Chain and Storage
Updated:
02/09/2026
595/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
CEVA Logistics Global Score (TPRM)
xxxx
logo
CEVA LogisticsTransportation, Logistics, Supply Chain and Storage
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CEVA LogisticsVery Poor
Current Score
595Ca (VERY POOR)
01000
5 incidents
-58.6 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
595Before Incident
AUGUST 2026
627Before Incident
Breach
07 Aug 2026CEVA Logistics
CEVA Logistics: Ace & Tate also reports data breach at logistics company

Ace & Tate Data Breach Linked to Logistics Partner

592After Incident
CRITICAL-35
CEV1786152029
Ace & Tate Reports Data Breach Linked to Logistics Partner Eyewear retailer Ace & Tate has notified customers of a data breach stemming from a security incident at an unnamed logistics partner. The breach, reported to the Dutch Data Protection Authority, follows a pattern seen in recent disclosures from Bijenkorf, Bol, ING, and Ajax suggesting possible involvement of CEVA Logistics. While financial data, usernames, and passwords were not exposed, compromised information may include names, shipping and billing addresses, email addresses, phone numbers, order details, and track-and-trace data. The company has warned customers to remain cautious of potential phishing attempts. No further details on the timeline or scope of the breach have been disclosed.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: names, shipping and billing addresses, email addresses, phone numbers, order details, track-and-trace dataIdentity Theft Risk: Potential phishing attempts
DATA BREACH
Type Of Data Compromised: Personal and order-related dataSensitivity Of Data: Moderate (PII, order details)Personally Identifiable Information: names, shipping and billing addresses, email addresses, phone numbers
AUGUST 2026
663Before Incident
Breach
06 Aug 2026CEVA Logistics
CEVA Logistics and Bol: Bol also warns of a data breach at a logistics partner

Cyberattack on CEVA Logistics Exposes Bol Customer Data

592After Incident
CRITICAL-71
BOLCEV1786004807
Cyberattack on CEVA Logistics Exposes Bol Customer Data A cyber incident targeting CEVA Logistics, a logistics and warehousing partner for Dutch online retailer Bol, has potentially exposed customer data. The breach was first flagged by De Bijenkorf, which had previously issued warnings about a similar incident involving the same company. Bol confirmed that its own systems remained unaffected, but customer information including names, addresses, phone numbers, email addresses, and order details may have been accessed or stolen. Payment details and passwords were not compromised. Affected customers are being notified directly. As a precaution, Bol temporarily took offline the product range of its sales partners linked to the affected site, leading to order cancellations and delays. CEVA Logistics also handles orders for other retailers, though it remains unclear whether their customers were impacted. The incident highlights the risks of third-party supply chain vulnerabilities in logistics operations.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Customer data including names, addresses, phone numbers, email addresses, and order detailsSystems Affected: CEVA Logistics systems (third-party logistics partner)Operational Impact: Order cancellations and delays due to temporary takedown of product rangeIdentity Theft Risk: Potential risk due to exposure of personally identifiable informationPayment Information Risk: None (payment details and passwords were not compromised)
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII), Order DetailsSensitivity Of Data: High (PII exposed, but payment details and passwords were not compromised)Data Exfiltration: Potentially (data may have been accessed or stolen)Personally Identifiable Information: Names, addresses, phone numbers, email addresses
JULY 2026
698Before Incident
Breach
30 Jul 2026CEVA Logistics
Pokémon Center and CEVA Logistics: Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Pokémon Center Customer Data Exposed in Third-Party Breach via CEVA Logistics

663After Incident
CRITICAL-35
CEVPOK1787070452
Pokémon Center Customer Data Exposed in Third-Party Breach via CEVA Logistics The Pokémon Center, the official retailer for Pokémon merchandise, confirmed a data breach stemming from a cyberattack on its logistics partner, CEVA Logistics. The incident, which occurred on July 30, exposed customer order details including names, email addresses, phone numbers, and physical addresses for orders shipped to the United Kingdom and Germany. While the Pokémon Center’s systems were not directly compromised, the breach disrupted operations, leading to delivery delays and cancellations for some customers. Payment card information was reportedly not affected. CEVA Logistics, which handles shipping for the retailer, notified the Pokémon Center of the attack, though the full scope of the breach and its impact on other clients remains unclear. The incident underscores the growing risk of third-party supply chain attacks, where vulnerabilities in partner networks can expose sensitive customer data. No further details on the attack’s origin or the number of affected individuals have been disclosed.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Customer order details (names, email addresses, phone numbers, physical addresses)Systems Affected: CEVA Logistics systems (third-party logistics partner)Operational Impact: Delivery delays and cancellationsIdentity Theft Risk: Potential risk due to exposure of personally identifiable informationPayment Information Risk: None (payment card information not affected)
DATA BREACH
NamesEmail addressesPhone numbersPhysical addressesSensitivity Of Data: Personally Identifiable Information (PII)Personally Identifiable Information: Yes
JULY 2026
734Before Incident
Breach
29 Jul 2026CEVA Logistics
CEVA Logistics: Steam hardware distributor hit by cyberattack, 'expect fake messages,' Valve warns — Europe vendor has personal information and hardware purchase details stolen

Steam Hardware Customers in Europe Warned of Phishing Risks After CEVA Logistics Cyberattack

663After Incident
CRITICAL-71
CEV1786364851
Steam Hardware Customers in Europe Warned of Phishing Risks After CEVA Logistics Cyberattack Valve has alerted European customers who purchased Steam hardware such as the Steam Deck or Steam Machine of potential phishing attempts following a cyberattack on its logistics partner, CEVA Logistics. The breach, detected on August 7, 2026, occurred between July 29 and August 1, exposing customer data held by CEVA for order fulfillment. The compromised information includes names, addresses, phone numbers, email addresses, and details about ordered products (type and price). However, Valve confirmed that sensitive data such as payment details, passwords, and Steam Guard codes was not accessed, as CEVA does not store this information. Valve warns customers to expect fraudulent messages via email, SMS, or phone, impersonating Steam, Valve, or delivery services. Attackers may demand fake customs or delivery fees or direct victims to phishing portals. Valve advises verifying URLs (e.g., help.steampowered.com for support) and avoiding embedded links in suspicious messages. The company also reiterated that legitimate Steam communications will never request passwords or Steam Guard codes. CEVA has isolated the affected systems, notified data protection authorities, and engaged external investigators to assess the incident. The breach underscores the risks of third-party supply chain attacks, even when primary platforms remain secure.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Phishing (Financial Gain)
IMPACT
Data Compromised: Names, addresses, phone numbers, email addresses, product details (type and price)Systems Affected: CEVA Logistics order fulfillment systemsOperational Impact: Isolation of affected systems, engagement of external investigatorsBrand Reputation Impact: Potential reputational damage to Valve and CEVA LogisticsIdentity Theft Risk: Moderate (PII exposed)Payment Information Risk: None (payment details not compromised)
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII), Order DetailsSensitivity Of Data: Moderate (PII exposed, but no payment or authentication data)Personally Identifiable Information: Names, addresses, phone numbers, email addresses
JULY 2026
815Before Incident
Ransomware
25 Jul 2026CEVA Logistics
Ceva Logistics and Boston Scientific: Ceva Logistics sued over theft of employee records during data breach

Cyberattack on Ceva Logistics Exposes Employee Data, Sparks Class Action Lawsuit

734After Incident
CRITICAL-81
CEVBOS1788361807
Cyberattack on Ceva Logistics Exposes Employee Data, Sparks Class Action Lawsuit A former employee has filed a class action lawsuit against Ceva Logistics, alleging the global freight provider failed to safeguard sensitive personal data stolen in a July cyberattack that disrupted operations across eight warehouses in the Netherlands and Europe. The breach, attributed to the CoinbaseCartel ransomware group, compromised employee information, including bank account details and Social Security numbers. The lawsuit, filed in late August in the U.S. District Court for the Southern District of Texas, claims Ceva neglected to implement adequate security measures despite a prior ransomware attack in September 2025, which the company never publicly disclosed. The complaint also alleges Ceva has not formally notified affected employees, leaving them vulnerable to fraud with the plaintiff reporting credit card fraud and increased spam calls as direct consequences. The filing seeks class action status, citing at least 100 impacted employees (potentially thousands) and demanding $5 million in damages for alleged negligence, breach of contract, and unjust enrichment. The lawsuit argues Ceva prioritized cost-cutting over security, using "cheaper, ineffective measures" that left data exposed. The incident coincides with leadership changes at Ceva, including the departure of two IT executives VP of IT Infrastructure Bryant Duke (November 2025) and Global CIO Susanne Shustein (March 2026). Parent company CMA CGM Group also reassigned Ceva’s CEO, Mathieu Friedberg, to a new role overseeing cybersecurity transformation, signaling broader concerns about enterprise-wide vulnerabilities. Healthcare Sector Also Targeted In a separate incident, McKesson Corp. confirmed a cybersecurity breach last week, with hackers allegedly the ShinyHunter group stealing customer and employee data from two business units. The group is demanding a $55 million ransom to prevent public release. McKesson joins a growing list of healthcare and medical device firms hit by ransomware in 2026, including Boston Scientific, which suffered a network outage in a recent attack.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Financial Loss: $5 million (claimed damages)Data Compromised: Bank account details, Social Security numbersSystems Affected: Warehouse operations in the Netherlands and EuropeOperational Impact: Disrupted operations across eight warehousesBrand Reputation Impact: YesLegal Liabilities: Class action lawsuit filedIdentity Theft Risk: Yes (credit card fraud, increased spam calls reported)Payment Information Risk: Yes
DATA BREACH
Type Of Data Compromised: Employee personal dataNumber Of Records Exposed: At least 100 (potentially thousands)Sensitivity Of Data: High (bank account details, Social Security numbers)Personally Identifiable Information: Yes (Social Security numbers, bank account details)
JUNE 2026
813Before Incident
MAY 2026
813Before Incident
APRIL 2026
813Before Incident
MARCH 2026
813Before Incident
FEBRUARY 2026
813Before Incident
JANUARY 2026
813Before Incident
DECEMBER 2025
809Before Incident
NOVEMBER 2025
809Before Incident
OCTOBER 2025
809Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CEVA Logistics ?
?
What was CEVA Logistics's A.I Rankiteo Cyber Score in August 2026 ?
?
What was CEVA Logistics's A.I Rankiteo Cyber Score in July 2026 ?
?
What was CEVA Logistics's A.I Rankiteo Cyber Score in June 2026 ?
?
What was CEVA Logistics's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CEVA Logistics's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CEVA Logistics's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CEVA Logistics's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CEVA Logistics's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CEVA Logistics's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CEVA Logistics's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CEVA Logistics's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on CEVA Logistics's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CEVA Logistics ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CEVA Logistics's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?