Ajax Confirms Customer Data Theft from Logistics Partner Hack

Ajax Confirms Customer Data Theft from Logistics Partner Hack

First seen 1 Sep 2026, 16:33 UTC www.at5.nlwww.welingelichtekringen.nl 52.5

Article Content

Browse articles
ThreatCluster

Ajax has confirmed that customer data was stolen in a recent hack of its logistics partner, CEVA. The breach was revealed earlier this month, indicating unauthorized access to CEVA's systems. Data from other companies, including Bol, Bijenkorf, ING, and Ace & Tate, was also compromised. Affected customers are those who made purchases from Ajax after January 1, 2024, with their names, email addresses, home addresses, and phone numbers potentially exposed. Ajax has stated that no payment information was stolen. The club has warned customers of increased phishing risks, advising them to be vigilant about communications that appear to be from Ajax. Reports suggest that the stolen data may be available on the dark web. The incident follows a previous data breach at Ajax that allowed for the theft of season tickets.

Key Points: • Ajax confirmed customer data theft from logistics partner CEVA. • Data from other companies, including Bol and ING, was also compromised. • No payment information was stolen, but phishing risks are heightened.

Timeline

2026-09-01
Ajax confirms data breach
Ajax announced that customer data was stolen in a hack of CEVA, its logistics partner, affecting customers who ordered after January 1, 2024.
AT5
Recent
Breach revealed
The breach was initially disclosed earlier in the month, indicating unauthorized access to CEVA's systems.
AT5
Recent
Data offered on dark web
Reports indicate that the stolen data from the breach may be available for purchase on the dark web.
AT5