August 7–8, 2026: The CEVA Logistics fulfilment breach that started with Bol and De Bijenkorf customer warnings has widened. AFC Ajax, ING (loyalty-points shoppers) and eyewear chain Ace & Tate have now told customers they are caught in the same third-party incident. Payment data and passwords are still not in the confirmed field lists — contact and order data are.
If you recently ordered from an Ajax fanshop, redeemed ING points for a physical gift, or bought glasses from Ace & Tate, treat this as your notice even if you never heard CEVA’s name on the packing slip.
Update August 10, 2026: Valve began notifying European Steam hardware customers, and CEVA confirmed the European warehouse intrusion to TechCrunch. See our Valve / Steam hardware briefing.
What happened
CEVA Logistics runs contract warehousing and e-commerce fulfilment for multiple European brands. When attackers reached systems used to pack and ship those orders, every client sharing that pipe inherited a customer-notification problem.
Bol named CEVA first. De Bijenkorf warned about a logistics partner without initially publishing the vendor. By August 7–8, Dutch Brief, Holland Daily, RetailDetail and Goal.com were reporting that Ajax, ING and Ace & Tate had joined the list. Ace & Tate’s customer email is the most specific on timing: an unauthorised party gained access on 1 August to part of the systems used for packing and shipping its orders.
CEVA, as of the expansion coverage, had not yet issued a detailed public statement of its own, saying it would respond later while not ruling out that personal data was leaked. That is why BreachHistory’s CEVA hub row still marks the vendor as not company-confirmed even though the client brands are.
Who is newly in scope
AFC Ajax
The Amsterdam club emailed supporters about a data incident at external logistics partner CEVA. Coverage says address, order and contact details of fanshop customers could be involved. Ajax reported the incident to the Dutch Data Protection Authority, warned that orders and returns may take longer, and told fans to expect phishing.
This is not framed as a breach of Ajax’s own ticket or membership databases. It is fulfilment data sitting with a shared warehouse partner — the same pattern as Bol and De Bijenkorf.
Ace & Tate
The eyewear retailer told customers a logistics partner’s packing and shipping systems were accessed on 1 August. It explicitly said eyeglass prescriptions, financial information, usernames and passwords were not compromised. That matters for a glasses brand: prescription data is the scare headline people invent if you do not rule it out.
Ace & Tate filed with the Dutch DPA and warned of possible fulfilment delays while online ordering continues.
ING Netherlands (loyalty shop only)
ING’s public framing is narrow: customers who bought a physical product through the loyalty points programme. A spokesperson said which data may have been exposed was still unclear, and the story is not being sold as a core banking-systems breach.
That distinction is important for phishing. Attackers will still try “ING security” themes. The confirmed logistics path is gifts and merchandise fulfilment, not your current-account login.
What was exposed — and what was not
Across the brand notices, the consistent negatives are payment details, bank account numbers, usernames and passwords. Ace & Tate adds prescriptions and financial data to that “not involved” list.
The consistent positives — or at least the cannot-be-ruled-out fields — are fulfilment contact data: names, addresses, phone numbers, email addresses and order details. Bol’s earlier notice was the most explicit on that inventory. Ajax’s language is similar for fanshop customers.
RTL Nieuws previously reported that Bol and De Bijenkorf customer data was already being offered on a dark-web forum. Combining those rows with Ajax or Ace & Tate order details would make “your package is held” texts much more convincing.
Zalando confirmed it experienced the CEVA incident operationally but said its customers’ data was not affected. Warehouse disruption and data exposure are related problems, not identical ones.
Timeline
- ~1 August 2026 — Ace & Tate: unauthorised access to packing/shipping systems used for its orders.
- ~3 August — Bol / De Bijenkorf detection window at the logistics partner (morning of Aug 3 in earlier retail notices).
- 5–6 August — De Bijenkorf and Bol customer warnings; Bol names CEVA; dark-web sale reports.
- 7–8 August — Ajax, Ace & Tate and ING publicly tied into the same wave; DPA filings noted.
Short windows between access, detection and multi-brand disclosure are normal for shared 3PL incidents. The phishing wave usually starts the same week the second and third brands hit the news.
Why one warehouse breach hits so many logos
Modern retail outsources the boring middle of commerce: receive stock, pick, pack, ship, handle returns. The 3PL needs enough personal data to put a box on a doorstep. When that environment is compromised, the brand’s own “we were not hacked” statement is both true and incomplete.
Customers hear brand names. Attackers hear a single extract with multiple merchant columns. That is why this CEVA Logistics data breach expansion matters more than any one of the new victims alone.
For security teams at other CEVA clients, the question is not whether Bol’s blog post was polite. The question is whether your fulfilment SKU data lives in the same tenant, site or integration that was isolated.
Who is at risk
Ajax fanshop buyers — especially recent orders and returns still in the CEVA pipeline.
Ace & Tate customers whose orders were packed or shipped through the affected systems around early August. Prescription holders should still watch medical/identity phishing, even though Rx fields were ruled out, because name and address alone fuel plenty of scams.
ING points redeemers who ordered physical merchandise — not every ING retail banking customer.
Earlier Bol and De Bijenkorf customers already in scope — the expansion does not shrink their risk; it raises the odds of blended phishing that name-drops multiple Dutch brands.
Employees and contractors at the affected brands who may see helpdesk callbacks about “CEVA access” — verify out of band.
Phishing you should expect
Real order numbers, real street addresses and real phone numbers will appear in fake SMS and email. Themes to burn on sight:
- “Your Ajax shirt is held at customs — pay €3.90”
- “Ace & Tate: confirm your prescription to release the parcel” (especially nasty because the company said Rx was not taken)
- “ING points gift delayed — unlock with iDEAL”
- “Bol / Bijenkorf / CEVA refund processing”
None of those should be handled from the message. Open the official app or type the official domain yourself.
What the companies and regulators said
Ajax, Ace & Tate, Bol and De Bijenkorf have been reported as notifying the Dutch Autoriteit Persoonsgegevens. ING’s public comments focus on the loyalty-shop population. Brands emphasise operational delays alongside privacy risk.
CEVA’s own customer-facing writeup was still pending in the expansion coverage. That gap does not erase the client confirmations. It does leave open questions about exact systems, sites and EU-wide headcount.
What you should do
- List recent orders from Ajax, Ace & Tate, Bol, De Bijenkorf and any ING points merchandise in late July–August 2026.
- Ignore delivery urgency that arrives by SMS or unexpected email — even if it quotes a real order.
- Check status only in official apps/sites you navigate to yourself.
- Do not “re-enter card details” for a package that brands say never lost payment data.
- ING customers: separate loyalty-shop noise from banking login prompts; report suspicious banking messages through official ING channels.
- Ace & Tate customers: be extra sceptical of any message asking you to re-upload a prescription photo.
- Ajax fans: watch ticket/resale phishing that piggybacks on the fanshop story.
- Keep screenshots of any brand emails for bank or Fraud Helpdesk reports.
Industry context
Shared logistics is the retail version of shared SaaS: concentration risk with someone else’s logo on the SOC 2. 2026 has already shown CRM and support-tool breaches cascading across brands; CEVA is the warehouse-floor analogue.
For boards, the procurement question is blunt. Who else packs beside you in that building, and do you get the same incident timeline they do? For consumers, the practical question is shorter: did a human need my address to ship this, and did that human’s employer just make the news?
Related BreachHistory records cover the full chain: CEVA hub, Bol, De Bijenkorf, Ajax, Ace & Tate, and ING NL loyalty shop.
Was I affected?
There is still no public headcount for Ajax, Ace & Tate or ING. If you placed a relevant order in the window and the brand emailed you, assume contact and order fields may be in play. If you never ordered, you are not in this logistics extract — though you may still see copycat phishing that borrows the headlines.
Dark-web listings already reported for Bol and De Bijenkorf mean some retail rows are outside the brands’ control regardless of later forensics nuance.
Comparing this to the first Bol / Bijenkorf notices
Nothing in the expansion contradicts the first week’s core facts. It widens the client list and sharpens Ace & Tate’s August 1 access date and “no prescriptions” assurance. ING’s loyalty-shop boundary is new detail that stops people from over-reading the bank’s involvement.
What remains missing is a CEVA-attested census and a system-level root-cause advisory. Until those arrive, treat brand notices plus dark-web reporting as the actionable floor.
For other brands still quiet
If you ship through CEVA in the Netherlands or nearby EU sites and you have not finished your own review, assume customers will ask why Ajax mailed them and you did not. Silence reads like negligence even when your SKU data was never in the touched system. Say what you know, including “not in scope,” with the same clarity Zalando used.
Canonical records and sources
Start with the CEVA Logistics August 2026 hub and the individual brand pages above.
Sources: Dutch Brief, Holland Daily, RetailDetail, Goal.com, earlier NL Times / RTL Bol/Bijenkorf coverage.
Published 2026-08-09. Expansion coverage; original Bol/De Bijenkorf cataloguing dated August 6.
Practical notes for households sharing an address
Fulfilment dumps are household-shaped. One person orders the Ajax jersey; another answers the door or the SMS. Brief everyone at the address that delivery-fee texts are hostile until proven otherwise. Do not argue with a courier who shows up in person without a tracking match in the official app — that is a different problem — but do not pay a stranger who texts like a courier.
If you use a parcel locker or neighbour drop-off, watch for “locker PIN reset” messages that arrive this week. Attackers love novel delivery mechanics because victims have less muscle memory for what a real message looks like.
What “no passwords” does not mean
Brands repeating that passwords were not taken is good news for account takeover of Ajax, Ace & Tate, Bol, De Bijenkorf and ING logins via this incident. It is not immunity from fraud. Address and order history are enough to socially engineer banks, payment processors and customer-support desks that reset accounts after “proof” of a recent purchase.
Reuse of the same password elsewhere remains your problem, not CEVA’s. This incident is still a reminder to rotate reused credentials if you ever typed the same password into a fanshop and a bank.
Returns, exchanges and slow warehouses
Ajax and Ace & Tate both warned that logistics problems may slow orders and returns. Scammers will impersonate returns desks. If you need to send something back, start from the order page you already have in the brand’s account UI — not from a fresh email with a QR code.
Slow shipping after a warehouse cyber event is normal. Urgent payment demands to “unstick” a parcel are not.
How this fits the 2026 retail risk picture
Retailers spent a decade concentrating inventory in fewer, smarter warehouses. Cybercriminals noticed. You do not need to defeat every brand’s WAF if one integrator holds the shipping file for half the high street. The CEVA Logistics data breach expansion is what that concentration looks like when the incident leaves the SOC ticket and enters customer inboxes under five different logos.
Compare that to first-party webshop breaches: those usually dump account hashes and saved cards. This wave dumps doorstep logistics. Different fields, same outcome for the person opening a text on the tram — a message that knows their name, street and what they bought.
Regulators will ask whether brands contractually required CEVA to notify them within hours, whether encryption covered the fields that walked out, and whether dark-web monitoring caught the Bol/Bijenkorf listings before customers did. Those answers will shape fines more than any single marketing email did.
Until headcounts arrive, individuals should act on brand notices rather than waiting for a perfect EU-wide number. The actionable advice does not change when the census moves from “unknown” to “184,000.”
For Ajax supporters specifically
Football clubs already fight ticket touts and fake hospitality emails every season. A logistics breach hands scammers a fresher order graph. If you bought training wear or a scarf through the official shop in the last few weeks, assume your shipping contact row is interesting to criminals even while the club investigates exact exfiltration.
Do not confuse this with older Ajax-related incidents covered elsewhere. This August event is the CEVA partner path. Use the club’s official site for merchandise status and report phishing that claims to be “Ajax security” demanding app passwords.
For Ace & Tate customers specifically
Glasses purchases are intimate enough that people panic about prescriptions. The company’s clear negative — prescriptions not compromised — should be the line you repeat to relatives who only saw the headline. Still freeze credit if you reuse identity documents across retailers for age checks, and still ignore parcel ransom texts.
If your frames were in transit on 1 August, prefer the retailer’s order tracker over any courier domain you do not recognise.