Decoding the world of cybersecurity

· ·

Ace & Tate confirms CEVA customer data theft

Ace & Tate says customer information was accessed and copied during a breach at logistics provider CEVA, expanding an incident first disclosed as a potential exposure in August.

Ace & Tate confirms CEVA customer data theft
Summary
  • CEVA Logistics has confirmed that Ace & Tate customer information was accessed and copied from systems used to process orders.
  • Ace & Tate says its own website and customer accounts were not accessed, while payment details, usernames, and passwords were not involved.
  • Dutch and UK regulators were notified as the logistics provider’s investigation established a wider confirmed impact.

Eyewear retailer Ace & Tate has confirmed that customer information was accessed and copied during a cyber incident at logistics provider CEVA, turning an earlier precautionary disclosure into a confirmed third-party data breach.

CEVA first informed Ace & Tate on 1 August that an unauthorised party had gained access to systems used to process the retailer’s orders. Ace & Tate stopped sharing data with the logistics provider on the same day, while CEVA blocked access to the affected systems and brought in external cybersecurity specialists.

At that stage, the full data impact was unclear. CEVA told Ace & Tate on 3 August that personal information could have been involved, prompting the retailer to notify the Dutch Data Protection Authority and the UK Information Commissioner’s Office on 5 August. Customers then considered potentially affected were contacted on 6 August.

The position changed on 10 September, when CEVA confirmed that Ace & Tate customer information had been accessed and copied. The retailer began contacting customers newly confirmed as affected on 14 September.

The information involved includes names, addresses, contact details, order information, and delivery data. Business customers may also have had company names and VAT numbers affected. Ace & Tate says payment details, bank-account numbers, credit-card data, usernames, passwords, and medical information were not involved.

The retailer also says its own website and customer accounts were not accessed. CEVA is monitoring whether information from the incident is being offered or published online, including on dark-web services, and Ace & Tate said there was no indication of publication at the time of its latest update.

The incident illustrates an exposure created by outsourced operational services. Logistics providers need customer information to fulfil orders, which places personal data outside the retailer’s direct technical environment. Compromise of that supplier can therefore produce a reportable breach even where the customer organisation’s own systems remain untouched.

The same dependency has appeared in other recent incidents. Trezor’s ShipMonk breach expanded after historical records remained in the logistics provider’s environment. The circumstances are different, but both incidents show how supplier access, retention, and deletion practices affect the eventual exposure created by outsourced fulfilment.

Ace & Tate’s response also demonstrates how the known scope of a breach can develop during forensic investigation. Its August notification described possible involvement based on the evidence available at the time. By September, CEVA’s investigation had established that information had actually been copied and that more customers were affected than had initially been identified.

That creates a regulatory and communications problem during third-party incidents. Organisations may need to notify authorities or customers before a supplier has established the complete impact, then update those disclosures as evidence develops. Waiting for complete certainty can delay important warnings, while earlier notices have to distinguish carefully between potential and confirmed exposure.

CEVA’s services resumed on 27 August after the company told Ace & Tate that an independent party had reviewed the affected systems and they could be returned to use. Ace & Tate says ordering, shipping, and returns are operating again.

The retailer has left open the possibility that further information could emerge. Its current position is that customers who have not received an incident email have no indication that their information was involved.

×