De Bijenkorf customer data exposed in cyberattack
What: Bijenkorf disclosed that a cyberattack on its logistics partner CEVA compromised customer personal data, prompting the department store to warn shoppers of heightened phishing risk.
Why it is important: The incident illustrates how a shared logistics vendor can become a single point of failure across multiple retail platforms, a third-party risk pattern already flagged as a growing share of retail cyber incidents.
CEVA Logistics, which handles logistics operations for both Bijenkorf and bol.com, suffered a cyberattack on 1 August. Bijenkorf confirmed on Thursday that the personal data of its customers had been compromised, including names, addresses, phone numbers and email addresses, together with descriptions of the payment method used, such as iDEAL or Wero. Financial details such as bank account numbers or card data, as well as login credentials, were not affected, since CEVA does not hold that information.
Both Bijenkorf and bol.com notified the Dutch Data Protection Authority immediately after the incident. The breach caused significant delays to orders, returns and refunds.
Because the exposed data increases the risk of convincing phishing attempts, Bijenkorf has urged customers to stay alert. It noted that genuine company emails are sent only from a specific verified address and always include an order number, and that it will never ask customers to make a repeat payment, change their password, or share payment details through a link.
CEVA has confirmed that remedial measures have since been taken, while bol.com says it has no additional findings beyond what it already communicated to its customers.
IADS Notes: The financial and reputational scale of retail data incidents was underscored when Coupang was hit with a record $409 million penalty (Inside Retail, June 2026) following a breach of over 33 million customer records, a case that also intensified regulatory pressure and calls for stronger governance. Retailers' own exposure to third-party and vendor-related incidents was similarly evident when Nike disclosed a possible data compromise (Reuters, January 2026), in a period when such breaches were already flagged as a growing share of retail cyber incidents. Payment infrastructure specifically has come under attack, with a skimming network found targeting global payment providers across e-commerce sites (TechNadu, January 2026), while the phishing risk that typically follows such exposures was detailed in an analysis of QR-code-based attacks on retail customers (RH-ISAC, February 2026), which linked rising phishing campaigns directly to prior data breaches.
De Bijenkorf customer data exposed in cyberattack
