JCtrans logo
Company Directory

Company Directory

Access the member directory, company profiles, and online inquiries to unlock multiple business opportunities. Our membership spans 181 countries with 12,000+ paid members and 770,000+ registered users.

View More

2026 FORBES CHINA SELECTION SERIES

inquiry_ranking_img

This selection aims to recognize outstanding logistics companies and core executives in multinational development.

Solutions

CMA CGM Subsidiary CEVA Faces Lawsuit Over Employee Data Allegedly Stolen in Cyberattack

CMA CGM Subsidiary CEVA Faces Lawsuit Over Employee Data Allegedly Stolen in Cyberattack

Logistics News
8-Sep-2026
Source: JCtrans

CEVA Logistics, a subsidiary of the CMA CGM Group, is facing legal action over a cyberattack in late July. On August 24, former CEVA employee Kevin Krupa filed a lawsuit in the U.S. District Court for the Southern District of Texas, alleging that the company failed to adequately protect employees’ personal information. The complaint claims that sensitive data, including bank account details and U.S. Social Security numbers, may have been stolen during the attack. The claims have not been proven in court, and no final ruling has been issued.

 

Key Highlights 

Proposed class action: A former CEVA employee has filed a proposed class action alleging that the company failed to adequately protect employees’ personal information. 

Sensitive data allegedly stolen: The complaint claims that bank account details, Social Security numbers, and other sensitive information may have been stolen. 

Eight European warehouses affected: The earlier cyberattack disrupted operations at eight CEVA warehouses in Europe and delayed some shipments.

 

Employee Data Allegedly Stolen as CEVA Faces Proposed Class Action

 

According to the complaint and FreightWaves, the plaintiff alleges that CEVA failed to maintain adequate cybersecurity safeguards during the attack, putting employees’ personal information at risk. The complaint identifies bank account details and U.S. Social Security numbers among the sensitive information involved. Krupa also claims that he experienced fraudulent transactions on his credit card and an increase in scam calls following the incident. He is seeking to have the case certified as a class action.

 

The complaint alleges that at least 100 employees were affected and that the actual number could be in the thousands. It seeks at least $5 million in damages. However, the number of people affected, whether the data was actually stolen, and whether CEVA bears legal responsibility remain subject to further investigation and court proceedings.


 

Earlier Cyberattack Affected Eight European Warehouses

 

The lawsuit stems from a cyberattack on CEVA in late July. On July 29, an intrusion affected parts of the company’s operations at eight European warehouses, including retail replenishment and e-commerce fulfillment activities. Some shipments were delayed.

 

CEVA subsequently notified affected customers and said the operational impact was confined to the eight European warehouses, with its other global systems unaffected. Some applications and services have since been restored. Earlier public reports focused mainly on the potential exposure of customer information and order data, including names, addresses, telephone numbers, and email addresses. The lawsuit has also raised questions about the security of employees’ sensitive personal information.

 

Cyberattacks Create Operational and Data Protection Risks for Logistics Companies

 

For third-party logistics providers, a cyberattack can affect warehouse operations, order fulfillment, and data security at the same time. As an integrated logistics provider, CEVA handles information relating to customers, orders, suppliers, and employees. If core systems are compromised, the impact may extend beyond the operations of a single warehouse.

 

The former employee’s lawsuit has added a potential legal dimension to the operational consequences of the earlier cyberattack. There is currently no public information indicating that the incident has caused widespread disruption across CEVA’s global logistics network. The main developments to monitor are the progress of the lawsuit, the data breach investigation, and any remedial measures CEVA takes for customers and employees.

 

Manufacturers, retailers, and cross-border e-commerce companies that rely on third-party logistics providers should assess cybersecurity, data protection, and business continuity capabilities alongside warehousing, transportation, and fulfillment performance. For operations involving large volumes of customer and order data, the security of a logistics provider’s systems has become an important part of overall supply chain resilience.

 

Sources and Disclaimer

Sources include FreightWaves, the public docket of the U.S. District Court for the Southern District of Texas, TechCrunch, and publicly available logistics industry information. This article is provided solely for reference by the international logistics and freight forwarding industry. Any further developments remain subject to the latest disclosures from the court, regulators, and the companies involved.

Community
Customer
Opinion Suggestion