2026 ING Netherlands — CEVA Logistics breach affecting loyalty-points shop physical orders (Aug)
Data compromised
Contact/order data for customers who bought physical products via the ING points shop may be involved; exact fields not fully published. Peer brands in the same wave state no payment data, usernames or passwords. Not a core banking-ledger breach per ING framing. Count unpublished.
Technical writeup
Company-confirmed third-party breach (loyalty fulfilment) — Dutch coverage (Holland Daily, Dutch Brief, Aug 7–8 2026) reports ING among organisations affected by the CEVA Logistics incident. An ING spokesperson said the issue concerns customers who bought a physical product via the points programme; which data may have been exposed was still unclear at reporting time, and the framing separates this from banking credentials. Peer retailers in the same wave state payment data, usernames and passwords were not taken. recordsAffected 0 pending an attested count.
Root cause
Third-party breach at logistics partner CEVA Logistics used to fulfil physical products ordered through ING’s loyalty points programme; ING says banking systems/data are not the issue described.