2026 Ace & Tate — CEVA Logistics packing/shipping systems access Aug 1; no Rx/payment/passwords (Aug)
Data compromised
Customer order/fulfilment contact data held in the affected packing/shipping systems may be involved. Ace & Tate states eyeglass prescriptions, financial information, usernames and passwords were not compromised. Count unpublished.
Technical writeup
Company-confirmed third-party breach — Ace & Tate emailed customers about a security incident at a logistics partner, stating an unauthorised party accessed packing/shipping systems on 1 August 2026 and that prescriptions, financial data, usernames and passwords were not affected (RetailDetail Aug 7). Dutch coverage links the incident to the same CEVA Logistics wave affecting Bol, De Bijenkorf, Ajax and ING. The retailer filed with the Dutch DPA and warned of possible order delays. recordsAffected 0 pending an attested count.
Root cause
Unauthorised party gained access on 1 August 2026 to part of the logistics systems used for packing and shipping Ace & Tate orders (company customer email / RetailDetail; partner identified in Dutch coverage as CEVA Logistics).