We are informing Ajax supporters about a security incident involving a logistics partner that is responsible for processing and shipping orders placed via Ajax.nl/shop. Together with the partner concerned, we are currently investigating what exactly happened and what the impact of the incident is. Although it is not yet clear whether any personal data is involved, we believe it is important to inform our supporters as a precaution.

On this page, you will find the most up-to-date information and any updates.

What happened?

CEVA is our logistics partner. On Monday, August 3, they informed us that unauthorized parties may have gained access to some of their systems and data. After the incident was discovered, CEVA immediately took measures to secure its systems and prevent further unauthorized access.

No Ajax systems were affected. The incident was limited to CEVA’s systems.

As a precaution, all data exchange between CEVA and Ajax was immediately suspended.

What does this mean for your order?

Due to the incident, processing orders and returns is taking longer than you are used to. Together with CEVA, we are doing everything we can to process and ship your order as quickly as possible. Our Fanshops remain open, and you can also continue to place orders online as usual.

Have you placed an order? You will have received an email with the new expected shipping timeframe by Wednesday, August 26 at the latest.

Are my details involved?

CEVA has since conducted further investigations and confirmed to Ajax that data was affected by the incident.

This concerns the following information you provided when placing orders since January 1, 2024. Only information that you provided yourself when placing an order may have been affected:

  • First and last name
  • Email address
  • Home address
  • Telephone number
  • Item number
  • Quantity of items

We can confirm that no payment details, bank account numbers (IBANs), credit card details, usernames or passwords were involved in this incident.

What should you look out for?

As it is still being investigated whether personal data is involved, we advise you to remain alert to messages that appear to come from Ajax. If the investigation shows that personal data is involved, there is an increased risk of phishing. In such cases, third parties may, for example, impersonate Ajax via email, text message, or phone.

Are you unsure whether a message is actually from Ajax? Please contact us directly via Ajax.nl/contact.

What happens next?

We take this incident very seriously. As a precautionary measure, we have reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Together with CEVA, we are closely monitoring developments.

As soon as the investigation provides more clarity and information becomes available that is relevant to you, we will inform you accordingly.

Questions?

We understand that this message may raise questions. Do you have any questions or concerns following this incident? We are doing everything we can to get answers to the questions that may arise as quickly as possible.

Is the answer to your question not listed here? Please feel free to contact us via Ajax.nl/contact. We are happy to help and will answer your questions as best as we can.