Ceva Logistics, a global freight and logistics company, is facing a proposed class action from a former employee who alleges the company failed to properly protect sensitive personal information that was allegedly stolen during a cyberattack that disrupted operations at several European warehouses.
Hackers breached Ceva Logistics’ systems and data in a late July attack that disrupted operations at eight warehouses that replenish stores and fulfilll e-commerce orders for retailers in the Netherlands and other European countries, FreightWaves previously reported. The lawsuit suggests the breach could have had ripple effects beyond the retailers and customers served by those facilities.
Why it matters: Ceva Logistics, a France-based company, is one of the world’s largest third-party logistics providers, with more than 1,000 warehouses worldwide. The company had $18.3 billion in revenue last year.
The lawsuit was filed last month in Houston federal court, where Ceva has its U.S. headquarters, by former employee Kevin Krupa.
Hackers stole employees’ personal information, including bank account information and Social Security numbers, the complaint said. Krupa alleges the breach could have been avoided had Ceva adopted proper security precautions following a similar incident nearly a year earlier.
In September 2025, the CoinbaseCartel hit Ceva Logistics with ransomware, according to the cyber intelligence platform SOCRadar. Ceva did not publicly comment on the incident.
The company also made changes among senior technology executives after the earlier attack. In November, Ceva’s VP of IT infrastructure for the Americas, Bryant Duke, announced his departure on LinkedIn. In March, the company’s global chief information officer Susanne Shustein announced on the social media platform that she had left Ceva. It is unusual to see two senior IT executives depart in such a short space of time.
During the summer, the CMA CGM Group, which owns Ceva, also moved Mathieu Friedberg from being CEO of Ceva to executive vise president of transformation and cyber at CMA CGM.
The appointment, which puts Friedberg in charge of cybersecurity at the parent company, suggests CMA CGM might see the cyber threat as a more enterprise-wide issue rather than one limited to Ceva Logistics, a source familiar with the company’s operations said on condition of anonymity because of concerns about retaliation.
Krupa’s complaint claims that Ceva’s cybersecurity practices left employees particularly vulnerable.
“Defendant’s systems were hacked by cybercriminals because Defendant failed to properly train its employees on cybersecurity and failed to implement reasonable security safeguards or protocols to protect the Class’s private information,” the filing says, claiming the company’s practices made employees “easy targets.”
The suit also says that Ceva has not formally notified employees about the breach. “The failure to notify has deprived the affected workers the chance to take action to protect themselves and limit the chance that their personal information could be used for fraudulent purposes, Krupa said.
Krupa said he himself was a victim of fraudulent activity with his credit card and had to cancel it. He also said there has been an uptick in spam and scam phone calls since the incident.
The complaint seeks class action status, alleging at least 100 employees have already been injured and the number of people affected could eventually reach into the thousands.
The suit seeks at least $5 million in damages and compensation. It charges Ceva with negligence, breach of implied contract and unjust enrichment.
The lawsuit also claims that Ceva opted for cheaper, ineffective security measures rather than deploying proper security and data-retention policies that could have prevented the breach.
Instead of providing a reasonable level of security, or retention policies, that would have prevented the data breach, Defendant calculated to avoid its data security obligations at the expense of Plaintiff and Class Members by utilizing cheaper, ineffective security measures,” the filing states.
“Employees were harmed as a direct result of the company’s purported failure to adequately protect their personal information,” Krupa said.
Healthcare sector also targeted
The Ceva case comes as cyberattacks continue to affect major companies across the healthcare and pharmaceutical supply chain.
McKesson Corp., one of the largest pharmaceutical distribution companies, confirmed last week in a government filing that it had identified a cybersecurity incident affecting its information systems.
In a statement issued Friday, McKesson said hackers had gained access to third-party data servers and removed sensitive customer information from two business units. The company also warned that it expected “intermittent service degradation.” Employee data was also reportedly stolen.
Bleeping Computer reported that the ShinyHunters hacker group was demanding $55 million in ransom in exchange for not publicly releasing the stolen private information.
McKesson is the latest healthcare or medical-device company to be targeted this year by cybercriminals using data theft and extortion. The attacks typically threaten to expose stolen information unless the targeted company agrees to pay a ransom.
Last month, Boston Scientific was also hit by a cyberattack that left a significant portion of its network offline, further highlighting the growing cybersecurity risks facing companies responsible for critical healthcare and supply-chain operations.





















