TechNewsReel
Live

Ajax Fan Data Exposed in Breach at Logistics Partner CEVA

A security incident at global supply chain provider CEVA Logistics has compromised customer data for the Dutch football club and other major retailers.

TechNewsReel Newsroom · August 11, 2026

Dutch football club Ajax has been caught in the fallout of a security breach at its logistics partner, CEVA Logistics. The incident forced the club to temporarily suspend data transfers, resulting in processing delays for fan orders and returns.

Unauthorized individuals gained access to systems operated by CEVA Logistics, which manages webshop order processing for the club. While Ajax confirmed its own internal systems were not affected, the breach at the third-party provider potentially exposed sensitive customer information. Confirmed exposed data may include names, email addresses, phone numbers, postal addresses, order histories, and VAT numbers for business customers.

A Wider Supply Chain Failure

This incident is not isolated to the sports world. Other prominent Dutch retailers, including bol and De Bijenkorf, were also affected by the same breach at CEVA Logistics. The scale of the vulnerability is underscored by the size of the provider; CEVA Logistics is a global supply chain giant founded in 2007 and acquired by the CMA CGM group in 2019. The company operates more than 1,300 locations worldwide and reported revenues exceeding $18.3 billion in 2025.

The Risk of Third-Party Vulnerabilities

This breach highlights a critical systemic risk in modern commerce: the third-party supply chain vulnerability. When a single logistics provider handles the backend operations for multiple unrelated organizations, a single point of failure can compromise the personal data of millions of customers across different industries. For Ajax, the consequence was an immediate operational hit, as the suspension of data transfers to protect fans led to a backlog in shipping and returns.

Regulatory Response and Next Steps

Ajax has moved to address the legal and regulatory requirements following the leak. "Ajax takes this incident very seriously," the club stated, noting that they have reported the incident to the Dutch data protection authority as a precautionary measure.

Observers will now be watching for the results of the regulatory investigation and whether CEVA Logistics will provide further details on the nature of the unauthorized access. For now, the club continues to manage the operational delays while the full extent of the data exposure is determined.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.