Ceva Logistics sued over theft of employee records during data breach |
Source |
American Shipper |
Post Date |
09/14/2026 |
|

Cyberattack compromised retailer accounts at company warehouses in Europe A former employee has filed a class action lawsuit against Ceva Logistics, alleging the freight giant failed to protect highly sensitive personal information stolen during a recent cyberattack that impacted operations in Europe. Hackers gained access to Ceva Logistics tems and data in late July, which disrupted operations at eight warehouses that provide store replenishment and e-commerce fulfillment for retailers in the Netherlands and other European countries,The legal action suggests that customers were not the only ones affected by the data breach. Why It Matters: France-based Ceva is one of the largest third-party logistics providers, with more than 1,000 warehouses worldwide. Last year the company generated $18.3 billion in revenue. Kevin Krupa, a former employee, sued Ceva Logistics late last month in U.S. District Court for the Southern District of Texas, in Houston, where Ceva? U.S. headquarters is located. The complaint alleges that the personal information of employees, including bank account details and social security numbers, was stolen during the cyber intrusion, which never would have happened had the company taken appropriate precautions following a similar incident a year earlier. The CoinbaseCartel initiated a ransomware attack on Ceva Logistics in September 2025, according to SOCRadar, a cyber intelligence platform. Ceva did not publicly disclose the incident. In November, Bryant Duke, Ceva? vice president of IT infrastructure Americas announced his departure on LinkedIn. Susanne Shustein, global chief information officer, informed fris and colleagues on the social media site in March that she had left the company. The departure of two IT leaders so close together is unusual. During the summer, parent company CMA CGM Group moved Mathieu Friedberg from CEO of Ceva to utive vice president of transformation and cyber at CMA CGM. The transfer to oversee cybersecurity implies the parent company believes the cyber threat is not isolated to Ceva Logistics and exts across the enterprise, said a source inside the company who did not want to be identified because of concerns about retaliation. ?ybercriminals were able to breach Defant? tems because Defant failed to adequately train its employees on cybersecurity and failed to maintain reasonable security safeguards or protocols to protect the Class? private information . . . rering [employees] easy targets,?Krupa said in the claim. The filing also claims Ceva has not formally notified employees about the breach, preventing them from trying to mitigate use of their personal information to commit fraud. Krupa said he experienced fraudulent activity on his credit card and was forced to cancel the card, and also suffered an increase in spam and scam phone calls. The complaint asks the court to grant class action status, saying that at least 100 employees have been harmed and that the number of affected persons could ext into the thousands. The suit seeks at least $5 million in compensation and damages for Ceva? alleged negligence, breach of implied contract, and unjust enrichment ?nstead of providing a reasonable level of security, or retention policies, that would have prevented the data breach, Defant instead calculated to avoid its data security obligations at the expense of Plaintiff and Class Members by utilizing cheaper, ineffective security measures. Plaintiff and Class Members, on the other hand, suffered as a direct and proximate result of Defant? failure to provide the requisite security,?the filing said.
 |
|
|

|