CEVA Logistics, a subsidiary of the CMA CGM Group, is facing legal action over a cyberattack in late July. On August 24, former CEVA employee Kevin Krupa filed a lawsuit in the U.S. District Court for the Southern District of Texas, alleging that the company failed to adequately protect employees’ personal information. The complaint claims that sensitive data, including bank account details and U.S. Social Security numbers, may have been stolen during the attack. The claims have not been proven in court, and no final ruling has been issued.
Key Highlights
• Proposed class action: A former CEVA employee has filed a proposed class action alleging that the company failed to adequately protect employees’ personal information.
• Sensitive data allegedly stolen: The complaint claims that bank account details, Social Security numbers, and other sensitive information may have been stolen.
• Eight European warehouses affected: The earlier cyberattack disrupted operations at eight CEVA warehouses in Europe and delayed some shipments.
Employee Data Allegedly Stolen as CEVA Faces Proposed Class Action
According to the complaint and FreightWaves, the plaintiff alleges that CEVA failed to maintain adequate cybersecurity safeguards during the attack, putting employees’ personal information at risk. The complaint identifies bank account details and U.S. Social Security numbers among the sensitive information involved. Krupa also claims that he experienced fraudulent transactions on his credit card and an increase in scam calls following the incident. He is seeking to have the case certified as a class action.
The complaint alleges that at least 100 employees were affected and that the actual number could be in the thousands. It seeks at least $5 million in damages. However, the number of people affected, whether the data was actually stolen, and whether CEVA bears legal responsibility remain subject to further investigation and court proceedings.

Earlier Cyberattack Affected Eight European Warehouses
The lawsuit stems from a cyberattack on CEVA in late July. On July 29, an intrusion affected parts of the company’s operations at eight European warehouses, including retail replenishment and e-commerce fulfillment activities. Some shipments were delayed.
CEVA subsequently notified affected customers and said the operational impact was confined to the eight European warehouses, with its other global systems unaffected. Some applications and services have since been restored. Earlier public reports focused mainly on the potential exposure of customer information and order data, including names, addresses, telephone numbers, and email addresses. The lawsuit has also raised questions about the security of employees’ sensitive personal information.
Cyberattacks Create Operational and Data Protection Risks for Logistics Companies
For third-party logistics providers, a cyberattack can affect warehouse operations, order fulfillment, and data security at the same time. As an integrated logistics provider, CEVA handles information relating to customers, orders, suppliers, and employees. If core systems are compromised, the impact may extend beyond the operations of a single warehouse.
The former employee’s lawsuit has added a potential legal dimension to the operational consequences of the earlier cyberattack. There is currently no public information indicating that the incident has caused widespread disruption across CEVA’s global logistics network. The main developments to monitor are the progress of the lawsuit, the data breach investigation, and any remedial measures CEVA takes for customers and employees.
Manufacturers, retailers, and cross-border e-commerce companies that rely on third-party logistics providers should assess cybersecurity, data protection, and business continuity capabilities alongside warehousing, transportation, and fulfillment performance. For operations involving large volumes of customer and order data, the security of a logistics provider’s systems has become an important part of overall supply chain resilience.
Sources and Disclaimer
Sources include FreightWaves, the public docket of the U.S. District Court for the Southern District of Texas, TechCrunch, and publicly available logistics industry information. This article is provided solely for reference by the international logistics and freight forwarding industry. Any further developments remain subject to the latest disclosures from the court, regulators, and the companies involved.

Last
Schedule Reliability Falls Across Major Asian Container Ports; Shanghai Drops to 21%
Schedule reliability at Asia’s major container ports deteriorated significantly in July. According to Sea-Intelligence, all 14 of

Next
CBP Considers Expanded Import Data Disclosures; Carriers and Freight Forwarders May Need to Prepare Documentation Earlier
U.S. Customs and Border Protection (CBP) is considering broader disclosure requirements for the supply chains of goods imported in




