Ace & Tate’s Copied Order Details Can Make the Next Scam Look Real
A scammer does not need a card number to sound convincing. A real order date, delivery address, product name, price and chosen store can make a fake parcel message feel like an ordinary part of a purchase. Ace & Tate has now confirmed that precisely this kind of customer information was accessed and copied from systems operated by its logistics partner, CEVA Logistics.
The Dutch eyewear company began contacting confirmed affected customers again on 14 September 2026 after receiving the new finding from CEVA on 10 September. The update changes the evidence from possible involvement to confirmed access and copying for the people being notified. Ace & Tate has not published the total number of affected customers, and it says there is currently no indication that the copied data is being offered or published online.
The copied fields describe a real transaction
Ace & Tate lists names and contact details, including email addresses, delivery and billing addresses and phone numbers. The copied information can also include order numbers and dates, delivery methods, the store linked to an order, product names and prices. Business-customer records may additionally include a company name and VAT number.
The company explicitly excludes payment details, bank account numbers, credit-card information, usernames and passwords. It also says prescription and other medical data was not stored in the affected CEVA systems. Ace & Tate’s own website and customer accounts were not accessed, according to its investigation.
Those exclusions reduce several direct risks. They do not make the copied data harmless. A message that names the product and delivery method can ask a customer to pay a small redelivery fee, confirm an address or open a tracking document. The requested payment details or password would be collected by the scam, not taken from the original breach. That is why post-breach phishing can create a new secret from old transactional context.
The breach happened in the delivery chain
On 1 August, CEVA told Ace & Tate that an unauthorised party had reached part of the logistics provider’s systems used to process orders. Ace & Tate stopped sharing data with CEVA that day. The logistics provider blocked access, brought in external specialists and took additional security measures.
CEVA said on 3 August that personal data might be involved. Ace & Tate notified the Dutch Data Protection Authority and the UK Information Commissioner’s Office on 5 August, then contacted the customers who were known to be potentially affected on 6 August. CEVA’s services resumed on 27 August after an independent party reviewed the restored systems. The investigation then established on 10 September that Ace & Tate customer data had in fact been accessed and copied, leading to the second customer notice on 14 September.
The statement does not identify the attacker, the initial access method or the number of Ace & Tate customers affected. It says CEVA works for many organisations across Europe and that several were affected by the same incident. Those facts support a supply-chain incident. They do not support combining every customer’s population into one unverified victim count.
What affected customers should do
Customers who received the 14 September notice should assume that the fields described in it were copied. Treat unexpected delivery messages, calls and emails with caution, particularly when they refer to a genuine order. Open the retailer or carrier’s website independently, use a saved bookmark or type the address yourself, and check the order from there. Do not rely on a link or phone number in an unsolicited message merely because its surrounding details are accurate.
Ace & Tate says customers do not need to change their account password because credentials were not involved and its accounts were not accessed. A password change may still be sensible where the same password is reused elsewhere, but it should not distract from the main risk in this incident: impersonation based on delivery and purchase context.
Be equally careful with messages claiming to be a further breach update. Verify any request through Ace & Tate’s published incident page or ordinary support route. The company says it will update that page and contact affected customers if relevant new findings emerge.
What organisations should learn from a warehouse copy
Retailers need logistics providers to know where an order is going and what operational steps it requires. That necessary data flow still needs limits. Contracts, diagrams and inventories should identify the exact fields transferred, their retention period, every system where copies persist and who can export them. Incident plans should also define how quickly a provider can tell each customer which records were actually accessed rather than only that a system was affected.
Communication quality matters too. Ace & Tate distinguishes its own systems from CEVA’s, lists included and excluded fields, explains why customers received a second message and avoids publishing a number it has not established. That specificity helps people respond to the risk that is present without creating fear about payment, account or medical data that the company says was not involved.
The lesson is not that shipping data is secretly payment data. It is that a delivery record carries enough truth to lend credibility to a lie. Once those details are copied outside the logistics system, customers need to verify the next message by its channel and request, not by how much it already knows.
Sources
- Ace & Tate, Security incident at our logistics partner, updated with confirmed copying and customer notifications on 14 September 2026.
- Ace & Tate, Dutch security incident notice, consulted 15 September 2026 to confirm the Netherlands-facing wording, affected-data list and customer guidance.
Continue the series: European National Cyber & Digital Law Series index


