Operations at eight Ceva Logistics warehouses in Europe were disrupted over the weekend by a cyberattack, causing shipping delays for many of the freight giant's retail customers with inventory stored in those locations, according to FreightWaves, citing a source close to the situation.
Affected customers were notified Aug. 1 that a cyber intrusion was impacting part of Ceva's contract logistics operation, the person told FreightWaves. Ceva Logistics has not commented publicly about the digital break-in, which is being investigated by the Dutch Data Protection Authority, other law enforcement agencies and the companies involved.
Attack scope
According to FreightWaves, the cyberattack disrupted operations at eight Ceva Logistics warehouses in Europe. Ceva is one of the largest third-party logistics providers, with more than 1,000 warehouses worldwide, and last year generated $18.3 billion in revenue, FreightWaves reported. The source familiar with the investigation said no other Ceva systems beyond the eight warehouses were impacted, and air, ocean, ground and rail transportation management activities are continuing without incident.
| Operations | Status |
|---|---|
| Eight affected warehouses | Disrupted; shipping delays for retail customers |
| Air, ocean, ground and rail transportation management | Continuing without incident |
| Remaining Ceva warehouse network (1,000+ sites) | Not impacted per source |
Retailer fallout
Online retailer bol and department store De Bijenkorf posted alerts Wednesday informing customers that hackers had compromised the information technology systems of a logistics vendor, and that some of their private data — but not credit card or payment details — was at risk, according to FreightWaves.
Bol said on its website:
"The partner's investigation has shown that unauthorized parties gained access to some of its systems and data. The incident involves two systems used to process orders from one of bol's distribution centres. No bol systems were affected. However, customer data processed through this location may have been accessed or copied."
Bol said it immediately suspended all data exchanges with this partner, and these will only resume once confirmed safe. Bol's products and those of selling partners stored at affected locations have been temporarily taken offline, and some orders have been canceled or may experience delays. All other bol logistics locations remain operational, bol added.
De Bijenkorf, which operates retail outlets in the Netherlands and sells goods online, told customers: "The processing of orders, returns, and refunds may take longer than customers are used to. Our stores remain open and online orders can be placed."
Recurring threat to freight
The freight transportation sector has been a frequent victim of cyber and ransomware attacks, FreightWaves noted. Shipping giant Maersk suffered a major attack several years ago, as did Seattle-based Expeditors International. Estes Forwarding Worldwide was hit by a cyberattack last summer.
| Company | Incident cited by FreightWaves |
|---|---|
| Maersk | Major cyberattack several years ago |
| Expeditors International (Seattle) | Major cyberattack several years ago |
| Estes Forwarding Worldwide | Cyberattack last summer |
| Ceva Logistics | Warehouse cyberattack over the weekend |
Shipper and operator guidance
The impact of the cyber intrusion varied by customer, the source told FreightWaves — some customers were more dependent on applications and services at the eight warehouses than others. Some applications and services at the distribution centers have been restored for certain customers, the source added. Shippers with inventory at Ceva's affected European sites should confirm with Ceva whether their orders are delayed, since bol has already taken products offline and De Bijenkorf expects longer processing times. Retailers that share data with Ceva's affected warehouses should also verify whether their data-exchange connections remain active, as bol suspended all data exchanges with the warehousing partner as a precaution.
Watch list
- The Dutch Data Protection Authority, other law enforcement agencies and the companies involved are continuing their investigation, according to FreightWaves.
- Some applications and services at the affected distribution centers have been restored for certain customers; further restoration may follow, the source said.
- Bol's data exchange suspension with the warehousing partner will remain in place until bol confirms it can safely resume, bol said.