SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Ceva cyber attack spreads across supply chain firms

Ceva cyber attack spreads across supply chain firms

Wed, 12th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

NCC Group has warned that the cyber attack on Ceva Logistics has become a wider supply chain incident affecting several organisations. The warning follows reported disruption at customers including Valve, Bol, De Bijenkorf and Ajax.

Gary Cannon, Global Transport Practise Leader at NCC Group, said the incident shows how a breach at a single logistics provider can spread quickly across sectors, causing operational disruption and potentially exposing personal information.

Ceva occupies a critical position in the supply chain, linking manufacturers, retailers, carriers and end customers. As a result, disruption can spread beyond its internal systems and affect inventory management, fulfilment and service continuity for companies that rely on its networks.

"This incident demonstrates how a cyber attack against a single logistics provider can quickly become a multi-sector supply chain event. Although the intrusion appears to have affected a limited number of warehouses, the consequences have cascaded across retailers, financial organizations, consumer brands and their customers, resulting in both operational disruption and the exposure of personal information," said Gary Cannon, Global Transport Practise Leader at NCC Group.

He said logistics groups are attractive targets because they sit at the centre of large supply chains and hold sensitive customer data. That combination gives attackers a way to cause disruption at scale without breaching each affected business separately.

Several of the organisations named in reports are consumer-facing brands, raising the prospect of delayed shipments as well as data exposure. The incident also shows how cyber attacks can spread from back-office systems into physical operations such as warehousing and transport.

"What makes logistics providers particularly attractive targets is their position at the center of large and complex supply chains. They connect manufacturers, retailers, carriers and end customers, occupying a uniquely sensitive role in the movement of goods and services. As a result, when their operations are disrupted, the effects can quickly extend beyond technology systems into inventory management, customer fulfilment and service continuity. Logistics providers also hold sensitive customer data, making them valuable targets for cybercriminals," Cannon said.

Wider impact

The warning points to a familiar weakness in cyber risk management: heavy reliance on suppliers that customers do not directly control. Businesses often depend on logistics providers, cloud operators and software vendors while having limited visibility into how those third parties manage security.

Cannon said this creates a blind spot, especially when a supplier handles customer information or supports day-to-day operations. A breach in that setting can lead to delayed services, lost productivity and damage to trust, even if the affected company's own network remains untouched.

"Attackers don't need to compromise dozens of organizations individually when breaching a single trusted supplier can create widespread disruption and impact across the supply chain," Cannon said.

He added that the immediate effects appear to extend beyond Ceva itself, with multiple organisations reporting disruption and potentially large numbers of customers exposed to risk if personal contact details were accessed. That matters because compromised contact data can be used in convincing phishing attempts based on real order or shipment information.

"The immediate impact appears to extend beyond CEVA itself, affecting multiple organizations and potentially large numbers of customers whose personal information may have been exposed. Several companies have also reported shipping disruptions and delays, highlighting how cyber incidents can increasingly affect real-world operations as well as digital systems," Cannon said.

Supplier risk

NCC Group said the incident highlights three linked issues: dependence on third parties, the physical effects of digital attacks and the risk of follow-on fraud after data theft. Those risks are becoming more closely connected as companies digitise warehousing, fulfilment and transport while sharing more data across partner networks.

For corporate security teams, the message is that supplier risk cannot be treated as a narrow compliance exercise. It requires continuous monitoring, testing and contingency planning, particularly for suppliers that are critical to fulfilment, customer service or revenue.

"Supply chain compromises often have a much larger blast radius than initially expected. NCC Group research has previously highlighted that organizations can be heavily affected by attacks against suppliers, even when their own networks remain uncompromised. The consequences can range from lost productivity and delayed services to reputational damage and reduced customer trust," Cannon said.

Cannon said businesses should assess critical suppliers on an ongoing basis, include security requirements in contracts and test how they would operate during a supplier outage. He added that logistics operators should maintain clear separation between operational systems and corporate IT, improve visibility of connected assets and strengthen detection and response.

"While no organization can eliminate cyber risk entirely, businesses can significantly reduce their exposure by treating supply chain security as a core element of organizational resilience rather than a compliance exercise," Cannon said.

"Organisations should conduct continuous monitoring and assessment of critical suppliers, ensure contractual security requirements are in place, and regularly test their ability to operate during a supplier outage. Visibility across the supply chain is essential, particularly where third parties handle sensitive customer data or support critical operational processes," he said.

The broader lesson, Cannon said, is that cyber resilience now depends not only on an organisation's own systems but also on the security and availability of the partners it relies on. "The key question for organizations now is not whether they use CEVA, but whether they have comparable dependencies elsewhere in their supply chain."