CEVA Logistics has revealed another layer of its recent security breach, confirming that attackers obtained information belonging to current and former members of its workforce. Previous disclosures surrounding the incident had focused largely on customer data processed by CEVA for companies using its logistics services.

 

 

In a message distributed internally, CEVA said unauthorized parties copied a mixture of personal and employment records. The information potentially affected is extensive, ranging from basic contact details to financial, family, and workplace records.

Among the data identified by CEVA are employee names, birth dates, home addresses, telephone numbers, email addresses, marital status, Social Security numbers, and copies of identity cards. Bank account information, salaries, pension details, emergency contacts, absence records, and notes from individual meetings were also stored within the affected systems.

Some records contained information about employees’ partners and children. An unusually specific piece of information potentially exposed was workers’ shoe sizes.

The company clarified that this does not mean every affected person had all of these details compromised. The categories of exposed information differ depending on the individual. CEVA has not yet disclosed how many former and current employees are involved.

Multiple user accounts were also compromised during the incident, according to information reported by Dutch outlet BNR. CEVA has since disabled those accounts.

The company reported the breach to the Dutch data protection authority and brought in external cybersecurity specialists as part of its continuing investigation.

The employee disclosure significantly broadens the known impact of the incident. CEVA had already emerged as the common logistics provider behind data breach notifications issued by several organizations whose customer information passed through its systems.

Those organizations include De Bijenkorf, bol, Ajax, ING, Ace & Tate, Valve, and Pokémon Center. The information exposed in those cases depended on what CEVA received from individual partners to provide logistics and delivery services.

Pokémon Center, for example, recently informed customers in Germany and the United Kingdom that information connected with their orders may have been obtained during the attack. The potentially affected records included customer names, addresses, email addresses, telephone numbers, and details of ordered products.

The latest development establishes that the attackers did not exclusively obtain information supplied to CEVA by its commercial partners. Internal personnel records were also copied, potentially exposing considerably more sensitive information about people who currently work for the company or did so in the past.

Leave a Reply