The CEVA Logistics data breach has exposed personal and employment information belonging to current and former workers, the company has confirmed. The incident had already affected several of the logistics group’s business partners and their customers.
CEVA says the compromised data differs between individuals. However, the available information suggests that the attackers accessed a wide range of highly sensitive employee records.
Employee records included personal and financial details
In an internal message to current and former staff, CEVA said attackers copied personal and work-related data from its systems.
The exposed information may include names, dates of birth, marital status, home addresses, email addresses and telephone numbers. In some cases, the records also contained Social Security numbers and copies of identity documents.
Furthermore, the compromised files may include bank account details, salary information, pension data and absence records. CEVA also listed emergency contact details, information about partners and children, and notes from individual staff meetings among the potentially exposed categories.
The company reportedly stored even employee shoe sizes on the affected systems.
Not every worker lost the same information
CEVA stressed that the breach did not expose every category of data for every current or former worker. Instead, the scope of the exposure varies by person, depending on the information held in the company’s records.
The company has not disclosed how many people the incident affects. It also remains unclear how much information the attackers removed from CEVA’s systems.
Reports indicate that the attackers compromised several user accounts during the incident. CEVA has since deactivated those accounts.
Investigation into the CEVA Logistics data breach continues
CEVA reported the incident to the Dutch data protection authority and says external cybersecurity experts are assisting with the investigation.
The breach first drew public attention after several organisations warned that customer information may have been affected through CEVA’s operations. Reported organisations include Dutch retailers De Bijenkorf and bol, football club Ajax, ING, Ace & Tate, Valve and the Pokémon Center.
CEVA Logistics operates freight management and contract logistics services worldwide. The company has more than 1,300 locations and employs over 110,000 people.
As the investigation continues, affected current and former employees may need to stay alert for phishing attempts, suspicious account activity and other signs that criminals could misuse their personal information.


0 responses to “CEVA Logistics Data Breach Exposes Employee Information”