CEVA Breach Exposes Delivery Data Across Eight Sites

A cyberattack on CEVA Logistics disrupted operations at eight European warehouses and exposed customer delivery information, forcing some facilities to revert to manual order processing while incident-response teams worked to contain the intrusion across connected systems.

The breach affected warehouses serving retail, financial services and consumer-goods customers. Exposed data included shipment schedules, recipient addresses and delivery windows - information that can be used to orchestrate theft, redirect cargo or map facility operating patterns.

Ilan Barda, CEO at Radiflow, a provider of operational-technology security, said in written responses to The Supply Chainer that logistics centers face two structural vulnerabilities: "The mixed IT/OT network enables lateral movement of the attacker from the IT network to the critical OT network. These facilities rely on extensive use of wireless networks providing an easy entry point for the attacker."

Breach Cost and Recovery Time

The incident underscores a broader risk pattern. According to the Verizon 2025 Data Breach Investigations Report, 30 percent of breaches involved third parties last year, double the 15 percent recorded the prior year. The Databarracks Data Health Check 2026 found that 26 percent of businesses suffered a cyber incident originating from their supply chain in the past 12 months. The IBM Cost of a Data Breach Report 2025 pegged the average cost of supply-chain breaches at $4.91 million, with 267 days required to fully resolve the incident.

Ilan Barda, CEO, Radiflow, "The mixed IT/OT network enables lateral movement of the attacker from the IT network to the critical OT network."
Ilan Barda, CEO, Radiflow, "The mixed IT/OT network enables lateral movement of the attacker from the IT network to the critical OT network."

Separation and Hardening

Barda identified three baseline controls for warehouse environments: separation of IT and operational-technology networks with restricted traffic flow through a firewall, hardening of access control to wireless access points, and deploying network intrusion-detection systems for early anomaly detection so attacks can be stopped before damage occurs. "On top of these three basic security controls it is recommended to conduct a security posture assessment of the site to map additional specific gaps and proposed mitigations," Barda told The Supply Chainer.

When warehouse-management or connected platforms are compromised, business continuity depends on network separation, reverting to backup copies of all OT device firmware and logic, and using manual processes for shipment orders, according to Barda.

Gary Cannon, Global Transport Lead at NCC Group, said in a published statement: "This incident demonstrates how a cyber attack against a single logistics provider can quickly become a multi-sector supply chain event. Although the intrusion appears to have affected a limited number of warehouses, the consequences have cascaded across retailers, financial organizations, consumer brands and their customers, resulting in both operational disruption and the exposure of personal information."

Dependency Questions

Cannon added that the breach should prompt organizations to examine third-party dependencies more rigorously: "Events like this should prompt organisations to ask difficult questions about their dependence on third parties - what access suppliers have to sensitive data, how disruptions would affect operations, and whether contingency plans are in place if a critical partner suddenly becomes unavailable. The key question for organisations now is not whether they use CEVA, but whether they have comparable dependencies elsewhere in their supply chain."

The eight affected warehouses represent a fraction of CEVA's European footprint, but the cascading impact across customer sectors illustrates how localized intrusions propagate when shipment data, order logic and tracking systems share common authentication and access layers.

← All stories