We are informing Ajax supporters about a security incident involving a logistics partner that is responsible for processing and shipping orders placed via Ajax.nl/shop. Together with the partner concerned, we are currently investigating what exactly happened and what the impact of the incident is. Although it is not yet clear whether any personal data is involved, we believe it is important to inform our supporters as a precaution.

On this page, you will find the most up-to-date information and any updates.

What do we know at this time?

CEVA is our logistics partner. They informed us on Monday 3 August that unauthorised parties may have gained access to part of their systems and data. After this was discovered, CEVA immediately took measures to secure the systems and prevent further access. No Ajax systems have been affected. The incident has been limited to CEVA’s systems.

As a precautionary measure, the exchange of data between CEVA and Ajax was immediately suspended. This will only resume once it has been established that this can be done securely. In addition, an investigation has been launched to determine how the incident occurred, which systems were affected, and whether personal data is involved.

What does this mean for your order?

Due to the incident, orders and returns are taking longer than you are used to. Together with CEVA, we are doing everything we can to process and ship your order as soon as possible. We will of course keep you informed about the status by email. As soon as we are able to provide a specific delivery timeframe, we will inform you immediately. Our Fanshops remain open, and you can continue placing orders online as usual.

Are my details involved?

We do not know this at this time. The investigation is still ongoing. Therefore, we cannot yet say with certainty whether supporters’ personal data is involved and, if so, which data is affected.

We can confirm that no payment details, bank account numbers (IBANs), credit card details, usernames, or passwords are involved in this incident.

At this moment, it is still unclear whether address details, order information, email addresses, and phone numbers are involved.

What should you look out for?

As it is still being investigated whether personal data is involved, we advise you to remain alert to messages that appear to come from Ajax. If the investigation shows that personal data is involved, there is an increased risk of phishing. In such cases, third parties may, for example, impersonate Ajax via email, text message, or phone.

Are you unsure whether a message is actually from Ajax? Please contact us directly via Ajax.nl/contact.

What happens next?

We take this incident very seriously. As a precautionary measure, we have reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Together with CEVA, we are closely monitoring developments.

As soon as the investigation provides more clarity and information becomes available that is relevant to you, we will inform you accordingly.

Questions?

We understand that this message may raise questions. Do you have any questions or concerns following this incident? We are doing everything we can to get answers to the questions that may arise as quickly as possible.

Is the answer to your question not listed here? Please feel free to contact us via Ajax.nl/contact. We are happy to help and will answer your questions as best as we can.