Names, Addresses and Order Details Possibly Leaked in Bol and de Bijenkorf Breach
Bol and de Bijenkorf have warned that names, addresses, phone numbers and order details may have leaked after a cyberattack on shared logistics partner CEVA. No passwords or payment data affected.
See more of Dutch Brief in your Google search results
Two of the best-known names in Dutch retail, the online store Bol and the department store de Bijenkorf, have warned their customers about a possible data breach. The leak did not happen at the shops themselves, but at a company that handles their deliveries, and it shows how a single weak link in the supply chain can affect several brands at once.
What happened
The breach was the result of a cyberattack on CEVA Logistics, an international logistics firm that carries out warehouse and shipping operations for both Bol and de Bijenkorf. According to Bol, unauthorised parties may have gained access to CEVA’s systems. The retailers stress that their own systems were not affected; the problem lies with a partner that processes their orders.
Bol says the incident relates to the handling of orders from one of its distribution centres, reported by several media to be in Waalwijk. Once the attack was discovered, CEVA moved to shut off the intruders’ access, and Bol says it halted its data exchange with CEVA and brought in external cybersecurity specialists, adding that the two will only resume working together once the systems are confirmed to be safe.
What data may have leaked
For customers who receive a warning email, the data that may have been exposed includes names, addresses, postcodes, email addresses, telephone numbers and details of their orders, such as order numbers and track-and-trace information.
Both companies say there is an important limit to the damage: at this stage there are no indications that payment details, passwords or login credentials were caught up in the incident. It is also not yet clear how many customers are affected. An external investigation into the cause, scale and consequences is under way, and the stolen data may be circulating among criminals.
SPONSORED
You’re overpaying your accountant. And they still don’t call you back.
Neno gives you a dedicated bookkeeper, automated admin, real-time financial insights and a free business bank account. Everything your business needs, in one place.
No chasing. No surprises. No unnecessary costs.
A delay that raised questions
The timeline has drawn some scrutiny. Bol says CEVA told it on 1 August that there may have been a breach. The companies notified the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) on 3 August, and affected customers were emailed on 5 August.
Asked by NOS why customers were not told sooner, a Bol spokesperson said the company had first needed to investigate thoroughly what had happened and which customers were affected. “That is something we immediately worked very hard on,” the spokesperson said. “We want to inform customers as well as possible in one go, and not two or three times.” Under European rules, companies must report a data breach to the regulator within 72 hours, but there is no fixed deadline for warning customers, only that it must happen without delay when there is a high risk to the people involved.
Delays to orders
There are practical knock-on effects too. Because of the security measures taken, the processing of orders, returns and refunds is running late, and some orders have been cancelled or may be delayed. Stock held at the affected location has been temporarily taken offline. The shops and websites otherwise remain open.
What customers should do
The most important thing to know is where the real risk lies. Because criminals may hold genuine details of people’s names and recent orders, the biggest danger now is targeted phishing: fake messages, by email, text or phone, that look convincing precisely because they refer to a real purchase. Both retailers have urged customers to be extra alert to this.
A few sensible steps follow from that. Be wary of any unexpected message about an order, a delivery problem, a refund or a payment, even if it quotes accurate details, and do not click on links or call phone numbers contained in such messages. If you want to check on an order, go to the retailer’s website or app directly rather than following a link. Although the companies say passwords were not leaked, it does no harm to use a strong, unique password for your accounts. And be aware that criminals may exploit the news itself by sending fake “data breach warnings”, so check carefully who a message is really from; the retailers are contacting affected customers directly.
If you receive a message you are unsure about, or think you may have been targeted, you can report it to the Fraud Helpdesk. Customers who have not received an email from Bol or de Bijenkorf have, for now, no indication that their data was accessed.




