Dutch bank ING has reported a data breach at logistics provider CEVA Logistics, where several other companies have also reported data exposure incidents.
After Dutch online retailer Bol and department store De Bijenkorf initially reported a potential data breach at their shared logistics provider, the list of affected organizations is growing. Bank ING, eyewear retailer Ace & Tate, and soccer club Ajax have now also confirmed related incidents.
The common link between the cases is international logistics provider CEVA Logistics, according to multiple reports. The company handles warehousing and order deliveries for all of the affected organizations and therefore had access to the customer data required for these services. CEVA itself said it could not rule out the possibility that personal data had been exposed. At least eight of the company’s European warehouse locations were reportedly affected.
Ace & Tate said an unauthorized party gained access on August 1 to part of the systems used for packaging and shipping orders.
At ING, the incident affects only customers who ordered physical products through the bank’s loyalty points program. Potentially exposed information includes names, addresses, phone numbers, email addresses, and details of ordered products. The bank stressed that neither its own systems nor customer bank accounts, payment data, savings, or login credentials were affected. ING has notified the Dutch data protection authority.
At Ace & Tate, potentially affected information includes names, delivery and billing addresses, email addresses, phone numbers, shipping methods, and shipment tracking data. According to the company, payment information, login credentials, and stored eyeglass prescriptions were not affected. Ace & Tate and soccer club Ajax have also notified the relevant data protection authorities. In Ace & Tate’s case, the company additionally notified the UK’s Information Commissioner’s Office (ICO).
Before ING: Bol and De Bijenkorf Customer Data Appears on the Dark Web
According to Dutch broadcaster RTL Nieuws, data belonging to Bol and De Bijenkorf customers is already being offered for sale on relevant dark web forums. An actor operating under a pseudonym claimed to have stolen records belonging to more than 400,000 Belgian Bol customers. The data allegedly includes names, dates of birth, phone numbers, email and delivery addresses, shipment tracking numbers, and order histories. Based on current findings, passwords and complete payment details do not appear to be included.
Bol said it was taking the claim seriously but had so far found no evidence of an actual attack on its own systems, which continue to operate normally. Media reports indicate that German online retailer Zalando has also been affected by the same CEVA incident.
Both ING and Ace & Tate are urging affected customers to remain particularly vigilant against phishing attempts and identity fraud. ING specifically advises customers never to share passwords, avoid clicking links in unsolicited messages, regularly check account activity, and contact the bank only through official channels if they have concerns. Customers should also report suspicious messages to the respective companies.
Shopping at the companies’ physical stores is not affected by the incident. However, the processing of orders, returns, and refunds may experience temporary delays.
(Editorial Team)