Major Dutch Retailers Suffer Delivery Delays and Data Exposure After Logistics Cyberattack
Utrecht, Wednesday 5 August 2026
A cyberattack on logistics provider CEVA Logistics has disrupted deliveries and exposed customer data for major Dutch retailers Bol and De Bijenkorf, highlighting critical supply-chain vulnerabilities.
Breach Details and Compromised Data
On 1 August 2026, the international logistics provider CEVA Logistics informed the Dutch e-commerce giant Bol of a cyberattack targeting two of its systems [3][5][6]. These specific systems are used to process orders from Bol’s distribution centre located at Veerweg 16 in Waalwijk [5][6]. While Bol’s own internal security systems, website, and applications remained entirely uncompromised, unauthorised third parties managed to gain access to CEVA’s database [2][5][6]. Consequently, customer information processed through this single distribution facility was potentially viewed or copied [2][6].
Scope of the Exposed Customer Information
The compromised customer data is extensive, encompassing names, physical addresses, postcodes, cities, telephone numbers, email addresses, order numbers, European Article Numbers (EANs), track-and-trace details, and order histories [3][5][6]. Despite the breadth of this exposure, both Bol and De Bijenkorf have reassured the public that highly sensitive information, such as passwords, bank account numbers, and payment details, was not stored on the affected systems and remains completely secure [1][2][5]. De Bijenkorf, which also utilises CEVA Logistics, was notified of the incident on Monday, 3 August 2026, and quickly initiated its own response protocols [2][8].
Operational Fallout and Supply-Chain Disruptions
The operational fallout from the breach has been immediate and disruptive. Following the detection of the cyberattack, CEVA Logistics intervened to block unauthorised access and implement emergency security measures [1][3][8]. However, this abrupt system shutdown has severely hampered logistics operations, resulting in significant delays for De Bijenkorf’s deliveries, returns, and refund processing, although its physical department stores and webshop continue to operate normally [1][2][8]. Because the Waalwijk distribution centre handles thousands to hundreds of thousands of packages daily, the total number of affected retail customers is expected to be substantial [5].
Bol’s Precautionary Measures and Offline Inventory
In response to the breach, Bol immediately suspended all data exchange with CEVA Logistics, stating that operations will only resume once the logistics partner’s security protocols are fully verified and restored [3][5][6]. To prevent further complications, Bol has also taken the inventory stored at the affected Waalwijk location offline and cancelled or delayed specific customer orders [4][5][6]. The company has engaged external cybersecurity specialists to conduct a thorough investigation alongside CEVA’s team, aiming to establish exactly how the breach occurred and secure the affected infrastructure [3][5].
Regulatory Reporting and Rising Supply-Chain Risks
To comply with European data protection regulations, Bol officially reported the data breach to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) on 3 August 2026, with De Bijenkorf following suit shortly thereafter [1][3][6]. Both retailers have begun directly contacting affected customers, advising them to exercise heightened vigilance against potential phishing attempts and fraudulent schemes [1][3][6]. This incident highlights the systemic vulnerabilities within modern digital supply chains, demonstrating that even when an enterprise maintains robust internal cybersecurity, its data security remains heavily dependent on the operational resilience of third-party logistics partners [GPT].
Sources & Ecosystem Partners
- www.ad.nl
- www.nu.nl
- tweakers.net
- www.rd.nl
- www.telegraaf.nl
- over.bol.com
- www.techzine.nl
- www.zeelandnet.nl