A cyberattack against CEVA Logistics disrupted operations across eight of the company's European warehouses, preventing goods from being shipped and causing delays for major customers.

The operational detail matters more than the label attached to the incident. When a warehouse management system goes offline, the physical building is fine, the staff are on site and the stock is on the shelves — but nothing can legally or practically move. Pick lists cannot be generated. Shipping labels cannot be printed. Customs paperwork cannot be produced. Inventory cannot be reconciled. The site becomes a very expensive storage unit.

The victims are the customers

The organisations feeling the sharpest effects are CEVA's clients, none of whom were attacked. Their goods are sitting in a facility they do not control, running against delivery commitments they still owe their own customers.

This is the defining characteristic of logistics sector incidents. A third-party logistics provider serves hundreds of shippers simultaneously. Their systems concentrate risk in a way that most procurement processes never model — a vendor security questionnaire asks about data protection, not about whether a ransomware event would strand your quarter's inventory.

Ask your logistics provider what happens to your goods if their WMS is offline for a week. If the answer is a shrug, that is your risk assessment.

Why logistics keeps getting hit

Several structural factors make the sector attractive to financially motivated attackers:

  • Low downtime tolerance. Perishable goods, contractual delivery windows and just-in-time manufacturing mean a day of outage carries immediate, quantifiable cost. That is precisely the pressure a ransomware negotiation is designed to exploit.
  • Heavy OT/IT convergence. Conveyor systems, automated storage and retrieval, sortation equipment and handheld scanners all connect to systems that also handle email and file shares. Segmentation is often theoretical.
  • Sprawling estates. Global providers operate hundreds of sites, many acquired rather than built, each with its own legacy systems and local IT decisions.
  • Deep partner integration. EDI connections, customer portals and carrier integrations create a large trusted-connection surface that is difficult to inventory, let alone monitor.

What manufacturing and retail teams should do now

If a logistics partner handles your goods, this incident is a prompt to test assumptions you have probably never tested:

  1. Map your single points of failure. Which providers, at which sites, hold enough of your inventory or throughput that a week of downtime becomes a board-level problem?
  2. Get contingency in writing. Ask specifically: can you retrieve goods manually? What is the manual fallback for shipping documentation? How long until an alternate site can take over? Vague reassurance is not an answer.
  3. Check your contracts. Most 3PL agreements have service level commitments and force majeure clauses that were drafted without cyber incidents in mind. Find out now which side of that line an outage falls on.
  4. Pre-qualify alternates. Standing up a new logistics provider takes weeks under normal conditions. Doing the paperwork in advance turns a crisis into an inconvenience.
  5. Include partner outages in tabletop exercises. Most exercises assume the incident is yours. Run one where it is not, and see how quickly your team discovers they have no visibility and no leverage.

For logistics operators

The controls that most reliably limit warehouse-level blast radius are unglamorous:

  • Network segmentation between corporate IT and warehouse operational systems, tested by someone actively trying to cross it.
  • Site-level isolation, so a compromise at one facility cannot trivially reach the others.
  • Offline, tested recovery for warehouse management systems specifically — not just the corporate file server.
  • Documented manual operating procedures that staff have actually practised, so a site can ship at reduced capacity with paper.
  • Privileged access management for the vendor accounts that support automation equipment, which are frequently shared and rarely rotated.

We will update this story as CEVA confirms further detail on the nature of the incident and the recovery timeline.