2026 AFC Ajax — CEVA Logistics partner breach; fanshop order/contact data at risk (Aug)
Data compromised
Address, order and contact details of supporters/fanshop customers could be involved (per club and Dutch coverage). Ajax and peer brands state payment details, usernames and passwords were not taken. Count unpublished.
Technical writeup
Company-confirmed third-party breach — AFC Ajax emailed supporters about a data incident at external logistics partner CEVA Logistics (Goal.com, Holland Daily, Dutch Brief, Aug 7–8 2026). The club reported the matter to the Dutch Data Protection Authority, warned that orders/returns may be delayed, and urged fans to watch for phishing. Coverage states address, order and contact details of recent fanshop customers could be involved while payment data, usernames and passwords were not. recordsAffected 0 pending an attested count.
Root cause
Third-party breach at logistics partner CEVA Logistics used for Ajax fanshop order fulfilment; Ajax says it is investigating whether personal data was taken. Ajax systems not described as the intrusion point.