Bol.com and De Bijenkorf breach after CEVA Logistics cyberattack
A cyberattack on the third‑party logistics provider CEVA Logistics was reported on 1 August. Unauthorized access to two systems at CEVA’s Waalwijk distribution centre allowed hackers to view or copy personal data of customers of Dutch online retailer Bol.com and luxury department‑store chain De Bijenkorf. Exposed information includes names, addresses, email addresses, phone numbers and order‑related details such as product, price and delivery data. No evidence has been found that payment card numbers, passwords or other login credentials were taken.
Both retailers said their own IT infrastructures were untouched. As a precaution, Bol.com halted data exchange with the affected warehouse, took part of its assortment offline and cancelled or delayed some orders. De Bijenkorf warned of slower deliveries, returns and refunds. Customers were notified by email on 6 August, and the incident was reported to the Dutch data‑protection authority (Autoriteit Persoonsgegevens). CEVA blocked the intrusion and engaged external cybersecurity specialists. Some media reported that the stolen data may already be offered on dark‑web markets, though the exact number of affected customers remains unknown.
Entities: Autoriteit Persoonsgegevens · Bol.com · CEVA Logistics · De Bijenkorf · Dutch Data Protection Authority · Waalwijk