According to www.freightwaves.com, a former employee has filed a class action lawsuit against Ceva Logistics in U.S. District Court for the Southern District of Texas, alleging the company failed to protect sensitive personal data stolen during a cyberattack that compromised systems across eight warehouses in Europe.
Cyberattack impacts operations and personnel
Hackers breached Ceva Logistics systems in late July 2026, disrupting store replenishment and e-commerce fulfillment services for retailers in the Netherlands and other European countries. The incident affected operations at eight warehouses and exposed highly sensitive employee information—including bank account details and social security numbers—according to the complaint filed by Kevin Krupa, a former employee. France-based Ceva Logistics generated $18.3 billion in revenue last year and operates more than 1,000 warehouses worldwide.
The lawsuit claims the breach would not have occurred had the company implemented appropriate cybersecurity safeguards following a prior ransomware attack by the CoinbaseCartel in September 2025. That earlier incident was not publicly disclosed by Ceva Logistics, despite its severity. The complaint further alleges that Ceva failed to train employees on cybersecurity and neglected to maintain reasonable security protocols, rendering staff “easy targets.”
Krupa reported fraudulent activity on his credit card, forcing cancellation, and experienced a marked increase in spam and scam phone calls. He stated:
“Cybercriminals were able to breach Defendant’s systems because Defendant failed to adequately train its employees on cybersecurity and failed to maintain reasonable security safeguards or protocols to protect the Class’s private information . . . rendering [employees] easy targets.” — Kevin Krupa, plaintiff
Leadership changes and enterprise-wide implications
In response to mounting cyber vulnerabilities, parent company CMA CGM Group reassigned Mathieu Friedberg from CEO of Ceva to executive vice president of transformation and cyber at CMA CGM during the summer. This strategic shift signals that the cyber threat extends beyond Ceva Logistics and is considered an enterprise-wide risk, according to an unnamed source inside the company. Two senior IT leaders departed within months: Bryant Duke, vice president of IT infrastructure Americas, left in November, and Susanne Shustein, global chief information officer, announced her departure in March.
The complaint seeks class action status, asserting that at least 100 employees have been harmed—with the total number potentially reaching into the thousands. It demands at least $5 million in compensation for alleged negligence, breach of implied contract, and unjust enrichment.
Broader sectoral pattern emerges
The Ceva case aligns with a wider trend: McKesson Corp. recently confirmed a cybersecurity incident affecting its information systems, with hackers stealing sensitive customer and employee data from third-party servers. The ShinyHunter hacker group is demanding $55 million in ransom to prevent public release of the data, according to Bleeping Computer. This follows a recent cyberattack on Boston Scientific, underscoring escalating threats across logistics and healthcare sectors.
Source: FreightWaves
Compiled from international media by the SCI.AI editorial team.