ING and Ace & Tate report security incident at logistics partner
De Bijenkorf, bol, and Ajax have fallen victim to a breach at a logistics partner. ING and Ace & Tate now join the list of victims.

Peter Boer/Bloomberg via Getty Images.
- ING and Ace & Tate warn customer data may be exposed due to a security incident at a shared logistics partner.
- Exposed ING data may include names, addresses, phone numbers, emails, and ordered product details, but not bank or payment data.
- Ace & Tate says exposed data may include contact and delivery details, with no payment or login credentials involved.
- The breach is linked to CEVA Logistics, which previously affected Ajax, bol, and De Bijenkorf in the Netherlands.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Global financial institution ING and optician chain Ace & Tate have reported that personal information of customers may have been taken due to a “security incident” at one of their logistics partners.
Both businesses were informed of the incident last week. The logistics partner, most likely CEVA Logistics, although this isn’t officially confirmed, told the companies it couldn’t rule out the involvement of customers’ personal data.
According to ING, its logistics partner processes personal information to fulfill orders for products purchased with loyalty points awarded to customers. The potentially affected information includes names, addresses, phone numbers, email addresses, and details about ordered products.
“It is important to note that this incident does not involve ING systems, customer bank accounts, payment information, savings balances, financial data, or login credentials. None of these data types are part of this incident,” the Dutch bank says in an online statement.
Because the personal information of a group of ING customers may have been affected, ING has submitted a notification to the Dutch data protection authority.
Affected customers are advised to remain vigilant for any fraudulent activities, including phishing and identity fraud.
“Never share passwords, don’t click on links in unsolicited messages, regularly review account transactions, contact ING through official channels if in doubt, and report suspicious messages to the relevant organization,” ING recommends.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Ace & Tate states that name and contact information, such as names, email addresses, postal addresses, billing addresses, phone numbers, delivery method, and tracking details, may have been exposed. It reassures its customers that no payment details, bank account numbers, credit card details, usernames, or passwords are involved in the incident.
Because a data breach can’t be ruled out at this stage, both the Dutch data protection authority and the UK’s Information Commissioner’s Office (ICO) have been informed of the incident.
The events at the logistics partner do not affect in-store shopping. However, orders, returns, and refunds may temporarily take longer to process than normally.
Last week, Dutch department store De Bijenkorf and online retailer bol disclosed they had become victims of a potential data breach at CEVA Logistics. Dutch soccer club Ajax also reported a potential breach due to an incident at the same logistics partner.