Ajax, ING and Ace & Tate hit by data breach
CEVA Logistics’ data breach has involved Ajax, ING and eyewear retailer Ace & Tate, according to Bol and De Bijenkorf. CEVA says it cannot rule out personal data exposure, while affected firms say no payment details, usernames or passwords were taken. ING says rewards-points physical product orders are affected. Ajax advises phishing vigilance; Ace & Tate warns of possible order delays.
How this was made

The 30-second read
Why it matters
The immediate trading relevance is cyber-risk and potential regulatory/reputational fallout for the named customer-facing brands and the bank, tempered by the statement that payment credentials were not taken.
Market read
This is a third-party data breach affecting named Dutch consumer and financial brands, with uncertain scope and no confirmed payment credential theft.
What to watch
Follow-on actions by privacy watchdogs (AP) and confirmation of which data fields were exposed (addresses vs emails/phones) could materially change perceived severity and any regulatory exposure.
Background
CEVA Logistics is reported to have had access to customer data needed to fulfill orders for Ajax, ING, and Ace & Tate; the breach came to light after Bol and De Bijenkorf warned customers.
Ticker impact
ING is named as a breach-affected bank, with customer rewards-points orders potentially exposed via CEVA Logistics access.
Low to modest downside risk for ING on any follow-on regulatory or customer-impact headlines; limited immediate fundamental impact from this report alone.
The text is specific that ING customers tied to rewards-points physical product orders were affected, but it also states no usernames/passwords or payment details were taken, and exposure type (email/phone/address) is unclear.
Market effects
Highlights third-party logistics cyber risk, which can raise compliance and insurance scrutiny across retail and financial services supply chains.
Primarily Dutch consumer and financial institutions, with potential spillover to other EU firms using similar logistics providers.
Third-party breach narratives can affect broader cyber-risk pricing for logistics and customer-data-heavy operators.
Counterpoint
Because the article says no payment details, usernames, or passwords were taken, the market may treat this as a contained incident with limited financial damage.
Key entities
- logistics firmCEVA Logistics
Third-party logistics provider implicated as having accessed customer data and potentially leaked personal details.
- bankING
Bank whose rewards-points customers who ordered physical products may have been affected.
- football clubAjax
Club advising supporters to be extra alert to phishing after the breach.
- eyewear retailerAce & Tate
Retailer warning customers about possible order delays and reporting the breach to the privacy watchdog.
- privacy watchdogAP
Dutch privacy regulator to which the affected companies reported the breach.
