Overview
- A cyberattack targeted a logistics provider that processes orders for Bol and De Bijenkorf, with reporting pointing to a CEVA-run distribution site in Waalwijk; both retailers say their own IT systems were not breached.
- Stolen records reportedly include names, addresses, email addresses, phone numbers and order details such as order numbers, product codes and track-and-trace data.
- Investigations are ongoing and parts of the stolen dataset are now being advertised for sale on the dark web, which speeds the chance the information will be used for scams.
- Bol and De Bijenkorf have halted data transfers with the affected location, filed reports with the Dutch data protection authority, and hired external cybersecurity specialists while CEVA has not issued a full public response.
- The Waalwijk site handles thousands to potentially hundreds of thousands of packages daily, so the total number of affected customers is unclear and those listed should expect more targeted scam messages and possible delays to orders, returns or refunds.