3 Supply Chain Breakdowns and the Lessons Behind Them
CEVA Logistics, Anheuser-Busch and Mumbai Port Authority have all appeared in reports over the past two weeks concerning critical operational breakdowns. The incidents involved a cyberattack that disrupted European warehouses, fraudulent drivers who collected two truckloads of beer, and a crane that overturned during heavy-lift cargo handling. Each failure appears to have involved, at least partly, a breakdown in operational judgment or control. What can supply chain leaders learn from these costly and potentially dangerous mistakes?
CEVA’s Secure-Delivery Promise Meets a Warehouse Cyberattack
A cyberattack against CEVA Logistics disrupted part of its European contract logistics operation, delayed shipments and exposed customer information associated with several major clients.
CEVA identified the intrusion on August 1 and said the operational impact was limited to eight warehouses. Customers of Valve, Bol, De Bijenkorf, Ajax, ING and Ace & Tate were reportedly among those affected. The exposed information potentially included names, addresses, telephone numbers, email addresses and order details. Bol temporarily stopped exchanging data with CEVA, removed products stored at affected locations from sale and warned that some orders could be delayed or cancelled.
The incident makes comments published by CEVA in February 2024 look uncomfortable in retrospect. Michael Rabaud, CEVA’s head of digital, data and innovation, said that ensuring the secure storage and transportation of customers’ goods was “of the utmost importance.” He concluded: “Our mission remains the same: to deliver securely for our customers.”
CEVA also said it had a centralized approach to cybersecurity across the CMA CGM Group and described protecting access to its systems as critical. The risk was hardly theoretical. The UK government’s 2025 Cyber Security Breaches Survey found that 74% of large businesses had identified a cyber breach or attack during the previous 12 months.
The lesson is that cybersecurity cannot be treated separately from warehouse continuity. A company can contain an intrusion technically while still leaving inventory unavailable, orders delayed and customers exposed. Distribution operators require tested offline processes for locating inventory, releasing orders and communicating with customers when the primary warehouse systems fail.
Fraudulent Drivers Collect 34,000 Cans of Beer
On August 17, two apparently fraudulent pickups removed approximately 34,000 cans of beer from an Anheuser-Busch distribution center in Montclair, California. The stolen products, valued at approximately $70,000, included Pabst Blue Ribbon and non-alcoholic Old Milwaukee. Police said one load worth about $45,000 was intended for Tucson but never arrived. Roughly an hour later, a second person allegedly presented fraudulent subcontractor documentation and collected another load worth approximately $25,000.
Anheuser-Busch’s publicly available C-TPAT protocols for warehouses and distribution centers say the company intends to “prove itself a leader in supply chain security.” The document requires facilities to restrict merchandise access to authorized personnel and states that a designated employee should supervise the removal of cargo.
Those commitments sound markedly different after two suspicious pickups reportedly succeeded within approximately one hour. The theft also reflects a wider change in cargo crime. Munich Re and BSI reported in June 2026 that 30% of US cargo theft incidents were strategic or fraud-driven. CargoNet recorded 3,594 supply chain crime events across the US and Canada during 2025, while estimated losses approached $725 million.
The lesson is that valid-looking documents are no longer sufficient proof that a driver is legitimate. Distribution centers must independently match the driver, vehicle, carrier and dispatch instruction against trusted records. A subcontractor change or unexpected pickup should require confirmation through a previously verified contact, not a telephone number or email address supplied by the arriving driver.

Mumbai Port’s Safety Drive Is Followed by a Crane Collapse
A shore-based mobile crane overturned during heavy-lift cargo operations at Mumbai Port’s Indira Dock. The crane tipped toward the M/V Vienna and a fire subsequently broke out. Two crane operators were injured and taken to hospital. The Mumbai Port Authority ordered an investigation and said it would examine possible negligence, dereliction of duty, safety violations or other non-compliance. Responsibility has not yet been established.
The timing is awkward. On May 11, Mumbai Port Authority Chairperson M. Angamuthu outlined initiatives intended to modernize port infrastructure and strengthen safety. The authority said it was implementing occupational health and safety systems aligned with ISO 45001 to improve risk management, incident prevention and safety compliance.
Less than four months later, a crane overturned during a project-cargo operation at one of the port’s docks.
The International Labour Organization’s guidance for ship and port operations specifically warns that containers or cargo can fall following the failure of cargo-handling equipment. Its code calls for lifting equipment to be properly tested, examined, maintained and operated within its safe working limits. The lesson is that a formal safety system matters only when it changes the decision made immediately before a lift. Equipment condition, load calculations, ground stability, crane positioning and operating conditions must be independently confirmed for each heavy-lift operation. Workers must also have clear authority to stop the job when conditions differ from the approved plan.
The Control Must Work at the Decision Point
The three incidents involved different risks, but the common failure was operational. CEVA needed continuity after a system breach. The distribution center needed reliable carrier authentication. Mumbai Port needed effective control of a high-risk lift.
Policies, technology investments and public commitments do not prevent failures by themselves. The real test is whether the control works when someone must decide whether to release a shipment, continue an operation or keep a warehouse running.

