Skip to content
Rush Commerce
Commerce & Retail Tech4 min read

Two freight breaches: your 3PL is in your data perimeter

Ceva Logistics and Uber Freight were both breached in two weeks. Your logistics vendor holds your customer data — and your notification obligation.

Bol did not get hacked. Its customers still got a breach notice. That is the whole lesson from two weeks in which both Ceva Logistics and Uber Freight confirmed intrusions — the freight layer holds your customer records, and when it leaks, the notification lands on your letterhead, not your vendor's.

What actually happened

Ceva Logistics. A cyberattack that began around July 29 hit eight European warehouses, TechCrunch reported. Ceva confirmed the intrusion to affected customers on August 1. The exposed data was ordinary commerce data: names, home addresses, postal codes, phone numbers, email addresses, order numbers, tracking details, and in some records gift-card messages, per The Record. Downstream: Dutch retailer Bol, De Bijenkorf, eyewear brand Ace & Tate, football club Ajax, banking group ING, and Valve's Steam hardware shipments in Europe. The Dutch data protection authority received reports from ten organizations. Ceva declined to answer questions about the volume of data taken.

Uber Freight. An extortion group calling itself Helix — which Google tracks as part of UNC6671 — claimed the company on its leak site, per TechCrunch. The group claims mailboxes, cloud storage drives, accounts-payable files, and dispatch documents. Uber Freight confirmed unauthorized access to part of its systems and repositories, said it identified, contained, and remediated the incident, and told Reuters operations were unaffected. The group's claim of roughly a million files is its own number, not a confirmed one.

Two different companies, two different attacks, one shared property: neither breach touched a retailer's own systems, and retailers had to notify anyway.

Why it matters for your business

Your data perimeter is not your infrastructure. It is every party holding a row that identifies your customer — and for anyone shipping physical goods, that list runs through a 3PL, a carrier, a returns processor, and whatever middleware ties them together. You do not control their patching. You still own the relationship with the person whose address leaked.

Four things worth doing this week:

Inventory who holds what. For each logistics vendor, list the exact fields you send and how long they keep them. Ceva reportedly holds customer records for up to 90 days. Do you know your carrier's number? Most operators don't.

Cut the field list. A warehouse needs a name, an address, and an order reference to pick and ship. It usually does not need the customer's email address, and it definitely does not need the gift-card message. Send a tokenized order ID and keep the identity mapping on your side.

Put hours in the contract. "Prompt notification" is not a term. A breach-notification SLA measured in hours, with a named contact, is. Ceva told customers on August 1 about an intrusion that started around July 29 — decide now whether that pace works for you.

Draft the customer email before you need it. The gap between a vendor's disclosure and your response is where trust is lost. Have the template, the segmentation query, and the approver settled in advance.

None of this is exotic. It's the same discipline as owning your product data instead of renting it: the systems that hold your customer relationship should be ones you can inspect, limit, and switch.

Key takeaways

  • Ceva Logistics: attack from around July 29 hit eight European warehouses; names, addresses, phones, emails, order and tracking data exposed across Bol, De Bijenkorf, Ace & Tate, Ajax, ING, and Steam
  • Ten organizations reported the incident to the Dutch data protection authority
  • Uber Freight confirmed unauthorized system access after extortion group Helix claimed mailboxes, AP files, and dispatch documents; operations unaffected
  • Neither breach touched a retailer's own systems — retailers still carried the customer notification
  • Audit what fields each logistics vendor holds and for how long, minimize them, and put a breach-notification SLA in hours into the contract

Do you know exactly what your fulfillment vendors hold about your customers? We map the data flowing out of your commerce stack, cut the fields that don't need to leave, and keep the identity layer on infrastructure you own. See how we build commerce systems, or send us your vendor list.

Sources: TechCrunch on Ceva Logistics, The Record, TechCrunch on Uber Freight.

  • #data-breach
  • #logistics
  • #3pl
  • #vendor-risk
  • #ecommerce
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.