Ajax caught in CEVA hack fallout, fans left waiting
Ajax is the latest victim of the data breach at CEVA Logistics.

Photo by Jeroen van den Berg/Soccrates/Getty Images.
- Ajax disclosed a security incident after hackers accessed parts of CEVA Logistics systems used for Ajax webshop order processing.
- Potentially exposed data includes names, addresses, emails, phone numbers, order histories, and some business customer VAT numbers.
- Ajax said its own systems were not affected, but data transfers with CEVA were temporarily suspended as a precaution.
- The CEVA Logistics breach also affected Dutch retailers including bol and De Bijenkorf, expanding concern over third-party supply chain risk.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Dutch football club Ajax has been informed of a “security incident” involving its logistics partner CEVA Logistics, which is responsible for processing and shipping orders placed in the Ajax webshop.
Ajax says it was notified of the incident last Monday. One or more “unauthorized individuals” gained access to parts of CEVA Logistics’ systems and data.
Although the Dutch soccer club doesn’t say what data may have been stolen or copied, the attackers may have exfiltrated a long list of personal data, including:
- Names
- Postal addresses
- Email addresses
- Phone numbers
- Order histories
- Business customer names and VAT numbers
As a result of the incident, orders and returns are taking longer than usual to process.
According to Ajax, none of its systems have been affected, and the incident remains limited to CEVA Logistics’ systems.
As a precaution, all data transfers between Ajax and its logistics partner have been temporarily suspended. Once it has been established that information can be exchanged safely, all data transfers will be resumed.
To learn more about how the incident could have occurred, which systems were affected, and whether any personal information was involved, an investigation has been launched.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
“Ajax takes this incident very seriously. As a precautionary measure, we have reported the incident to the Dutch data protection authority. Together with CEVA, we are closely monitoring developments,” the Dutch football club said in a press release.
CEVA Logistics is a global logistics and supply chain company that operates in both freight management and contract logistics. The company was founded in 2007 and purchased by the CMA CGM group in 2019.
CEVA Logistics has over 1,300 locations worldwide and employs over 110,000 workers. The company generated over $18.3 billion in revenue in 2025.
Last week, bol, the largest online retailer in the Netherlands, reported that the personal information of an undisclosed number of customers may have been stolen as a result of the security incident at CEVA Logistics.
Dutch department store De Bijenkorf was also involved in a potential data breach because of an incident at an external logistics partner.