LogisticsIndustry ContextWednesday, September 2, 20264 min read

Ceva Logistics sued over theft of employee records during data breach

Freightwaves21h agogeneral
Ceva Logistics sued over theft of employee records during data breach
Executive Summary

A lawsuit filed against Ceva Logistics alleges the harm from a recent cyberattack extended beyond warehouse customers to employees. The post Ceva Logistics sued over theft of employee records during data breach appeared first on FreightWaves.

Source Lens

Industry Context

Useful background context, but lower-priority than direct platform, community, or operator intelligence.

Impact Level

medium

Use this briefing to decide whether your team needs an immediate workflow, policy, or reporting change.

Key Stat / Trigger

No single quantitative trigger surfaced in this report.

Focus on the operational implication, not just the headline.

Relevant For
Brand SellersAgencies

Full Coverage

A former employee has filed a class action lawsuit against Ceva Logistics, alleging the freight giant failed to protect highly sensitive personal information stolen during a recent cyberattack that impacted operations in Europe.

Hackers gained access to Ceva Logistics systems and data in late July, which disrupted operations at eight warehouses that provide store replenishment and e-commerce fulfillment for retailers in the Netherlands and other European countries, as FreightWaves reported. The legal action suggests that customers were not the only ones affected by the data breach.

Why It Matters: France-based Ceva is one of the largest third-party logistics providers, with more than 1,000 warehouses worldwide. Last year the company generated $18. 3 billion in revenue. Kevin Krupa, a former employee, sued Ceva Logistics late last month in U. S. District Court for the Southern District of Texas, in Houston, where Ceva’s U. S.

headquarters is located. The complaint alleges that the personal information of employees, including bank account details and social security numbers, was stolen during the cyber intrusion, which never would have happened had the company taken appropriate precautions following a similar incident a year earlier.

The CoinbaseCartel initiated a ransomware attack on Ceva Logistics in September 2025, according to SOCRadar, a cyber intelligence platform. Ceva did not publicly disclose the incident. In November, Bryant Duke, Ceva’s vice president of IT infrastructure Americas announced his departure on LinkedIn.

Susanne Shustein, global chief information officer, informed friends and colleagues on the social media site in March that she had left the company. The departure of two IT leaders so close together is unusual.

During the summer, parent company CMA CGM Group moved Mathieu Friedberg from CEO of Ceva to executive vice president of transformation and cyber at CMA CGM.

The transfer to oversee cybersecurity implies the parent company believes the cyber threat is not isolated to Ceva Logistics and extends across the enterprise, said an a source inside the company who did not want to be identified because of concerns about retaliation.

“Cybercriminals were able to breach Defendant’s systems because Defendant failed to adequately train its employees on cybersecurity and failed to maintain reasonable security safeguards or protocols to protect the Class’s private information... rendering [employees] easy targets,” Krupa said in the claim.

The filing also claims Ceva has not formally notified employees about the breach, preventing them from trying to mitigate use of their personal information to commit fraud. Krupa said he experienced fraudulent activity on his credit card and was forced to cancel the card, and also suffered an increase in spam and scam phone calls.

The complaint asks the court to grant class action status, saying that at least 100 employees have been harmed and that the number of affected persons could extend into the thousands.

The suit seeks at least $5 million in compensation and damages for Ceva’s alleged negligence, breach of implied contract, and unjust enrichment “Instead of providing a reasonable level of security, or retention policies, that would have prevented the data breach, Defendant instead calculated to avoid its data security obligations at the expense of Plaintiff and Class Members by utilizing cheaper, ineffective security measures.

Plaintiff and Class Members, on the other hand, suffered as a direct and proximate result of Defendant’s failure to provide the requisite security,” the filing said. Healthcare sector attacked In related news, pharmaceutical distribution giant McKesson Corp.

, last week confirmed in a government filing that it had discovered a cybersecurity incident affecting its information systems. In a statement on Friday, it said hackers broke into third-party data servers and removed sensitive customer data within two business units, and that the company expected “intermittent service degradation.”

Employee data was also stolen. Tech site Bleeping Computer said the ShinyHunter hacker group is demanding $55 million in ransom to not publicly release the private data. McKesson is the latest healthcare or medical device maker to be victimized this year by cyber criminals that extort companies into paying ransoms to keep data from being released.

Boston Scientific was the target of a cyberattack last month that knocked much of its network offline. Click here for more FreightWaves/American Shipper stories by Eric Kulisch. Write to Eric Kulisch at ekulisch@freightwaves. com.

RELATED STORIES: Cyberattack on Ceva Logistics warehouses in Europe impacts retailers CMA CGM hires hires FedEx executive Moebel to lead Ceva Logistics Ceva Logistics poised to acquire European final-mile courier Paack Colis Privé expands last-mile delivery business into Spain and Portugal The post Ceva Logistics sued over theft of employee records during data breach appeared firs

Original Source

This briefing is based on reporting from Freightwaves. Use the original post for full primary-source context.

View original
LinkedIn Post Generator

Style

Audience