← Blog

Bol & De Bijenkorf Breach: CEVA Logistics Hit, Data Sold

Share on X

August 6, 2026: Two of the biggest names in Dutch retail told their customers to expect phishing this week, and neither of them was hacked. The breach happened at CEVA Logistics, the contract logistics giant that packs and ships their orders. By the time Bol named the vendor on Thursday morning, RTL Nieuws was already reporting that Bol and De Bijenkorf customer data was for sale on the dark web.

This is the shape most retail data breaches take in 2026. Nobody picked the lock on the front door of a €5 billion webshop. Someone got into the order-handling systems of a distribution centre, and two separate brands had to write to their customers about it.

Here is what each company has actually confirmed, what nobody knows yet, and what to do if you ordered from either retailer this summer.

What happened

De Bijenkorf, the Netherlands' premium department store chain, went first. On Wednesday, August 5 it warned customers of a possible data breach at one of its logistics partners. A spokesperson said the security breach was officially detected on the morning of Monday, August 3. The retailer would not name the partner, but did volunteer two useful details: the vendor handles logistics "in the broadest sense of the word," and it is not a parcel delivery service such as PostNL or DHL.

Bol followed on Thursday, August 6, and was more specific. In a statement and in messages to potentially affected customers, the online retailer said unauthorised parties had accessed a logistics partner's systems, that customer information may have been viewed or copied, and that the partner in question was CEVA Logistics — the company responsible for processing and delivering orders from one of Bol's distribution centres.

Bol was careful about one point, and it matters: Bol's own systems were not affected. The exposure is limited to data that sat in the affected CEVA system for recent orders shipped through that one centre.

Later on Thursday, RTL Nieuws reported that the leaked information was already being offered for sale on a dark-web forum — covering customers of both retailers. That single detail turns this from a precautionary notice into an active fraud risk, because criminals buying that data are buying it to use.

The timeline so far

  1. Monday, August 3, morning — the breach is officially detected at the logistics partner. The vendor blocks the unauthorised access, adds security measures, and shuts down specific data systems to isolate the threat.
  2. Wednesday, August 5 — De Bijenkorf warns customers, reports to the Dutch Data Protection Authority, and acknowledges delays in orders, returns and refunds.
  3. Thursday, August 6, morning — Bol warns customers, names CEVA Logistics, and confirms it also filed with the regulator.
  4. Thursday, August 6 — RTL reports the stolen data is on sale on the dark web.

Neither retailer has published a count of affected customers. Bol said plainly that it cannot yet determine how many people are involved. No ransomware or extortion group had claimed the intrusion publicly at the time of writing, and CEVA Logistics had not issued its own statement.

What was exposed

Bol gave customers a concrete field list. Attackers may have accessed:

  • Names
  • Street addresses, postal codes and places of residence
  • Phone numbers
  • Email addresses
  • Order details

De Bijenkorf's description is shorter and less certain, because its investigation is younger: it cannot rule out that names, contact details and data related to online orders ended up in the wrong hands.

None of that is a password dump. It is something arguably more useful to a fraudster: a verified list of real people, at real addresses, who really did just buy something specific from a shop they trust.

What was not exposed

Both retailers are unusually clear here, and the wording is worth reading closely.

Bol said it has found no evidence so far that payment data, passwords or account login credentials were exposed. De Bijenkorf said no payment details, bank account numbers or passwords were involved in the incident.

So: this is not a card-breach story, and there is no indication you need to change your Bol or Bijenkorf password because the credentials themselves leaked. What this is is an order-data breach, which drives a different kind of attack — one that works on people rather than on payment systems.

How one vendor breaks two retailers

CEVA Logistics is not a courier. It is a contract logistics provider owned by shipping group CMA CGM, and the work it does for retailers is warehousing and fulfilment: receiving stock, storing it, picking and packing orders, and handing shipments to carriers. To do that, it needs the same order data the retailer holds — who ordered what, and where it goes.

That is why a single intrusion at one distribution centre can produce two brand-name breach notices in 24 hours. The retailers' own e-commerce platforms, payment stacks and account systems can be perfectly intact while the vendor that physically fulfils the orders holds a copy of the customer list that matters most: recent orders, still in flight.

The operational fallout tells you how deep the containment went. Bol pulled products stored at the affected facility from sale and cancelled or delayed some orders. De Bijenkorf reported delays in orders, returns and refunds, explaining that part of the disruption came from the partner shutting specific data systems down entirely. You do not switch off order-processing systems in the middle of the week for a minor alert.

What we still do not know

Three gaps are worth naming, because they will shape the next two weeks of this story.

The number. Neither retailer has an affected-customer count. Bol's framing — data "stored in CEVA's affected system for recent orders processed through the impacted distribution centre" — suggests a bounded window rather than a full historical customer database, but bounded is not small. Bol serves roughly 13 million customers across the Netherlands and Belgium; a few weeks of orders from one fulfilment centre is still a very large list.

Whether it is one breach or two. De Bijenkorf has not named its partner. Bol named CEVA. Reporting has treated CEVA as the likely common vendor, and the timing, the description and the identical containment pattern all point that way — but as of publication De Bijenkorf has not confirmed it, so treat the link as strongly implied rather than established.

Who did it. No group has claimed the attack. Data appearing on a dark-web forum this quickly is more typical of straight data-theft-and-sale operations than of the big-name ransomware brands that prefer to post a countdown clock and negotiate. That may change.

Who is at risk

Recent Bol customers whose orders shipped from the affected distribution centre are the primary group. You will not know from the outside which centre handled your parcel, so if you ordered in roughly the past few weeks, assume you may be on the list until Bol tells you otherwise.

De Bijenkorf online shoppers are in the same position with less clarity, since the retailer is still determining whether data was actually taken.

People who used a gift or delivery address. Order data includes the delivery address, which means someone else's name and address may be in the exposed set alongside yours. If you sent a gift, the recipient could receive the phishing rather than you.

Marketplace sellers and business customers should watch invoice fraud specifically. Detailed order records are raw material for convincing supplier-payment scams.

CEVA's other clients. This is the uncomfortable one. A contract logistics provider runs fulfilment for many brands. If the intrusion touched systems shared across accounts, other retailers may yet issue their own notices. Nothing published so far says that happened — but it is the first thing security teams at CEVA's other customers should be asking.

The scams that follow order-data theft

Generic advice to "stay alert" is useless. Here is what the fraud built on this specific data set actually looks like.

The order that already exists. An email or SMS naming your real recent purchase, your real name, and the last four digits of nothing at all — because it does not need card data to be convincing. It says the parcel is held, or the address needs confirming, and asks for a small payment. In the Netherlands this usually arrives as an iDEAL payment request for €0.99 or €1.50, which is designed to look trivial and to get you into a bank-authorisation flow.

The refund that never comes. Especially potent right now, because De Bijenkorf has publicly said refunds are delayed. "Your refund could not be processed, confirm your bank details" lands very differently when the retailer has already told you refunds are late.

The phone call from "customer service." Order data lets a caller open with facts only the retailer should know. The ask that follows is either a bank-app confirmation or remote-access software. Neither retailer will ever ask for either.

The look-alike domain. Expect fresh registrations imitating both brands, especially around "bezorging" (delivery), "retour" (returns) and "terugbetaling" (refund).

The rule that defeats all of it: never navigate from the message. Open the retailer's app or type the address yourself, and check the order status there.

The Dutch pattern in 2026: third parties, not front doors

Security analysts quoted by NL Times put this incident in a trend that has defined the Dutch year: attackers going after third-party supply-chain vendors and IT subcontractors instead of trying to break a major brand's own infrastructure.

The evidence is not subtle. In April, patient data was reported at risk after a hack at healthcare software supplier ChipSoft, whose systems sit inside most Dutch hospitals. In July, supermarket chain Lidl warned customers of a data leak. Also in July, NL Times reported that Dutch municipalities are still leaking citizen data nine years after being ordered to tighten security.

Vendors are the efficient target. One intrusion, many brands, and each brand can honestly tell its customers that its own systems were never touched — which is true, and which is also cold comfort to the customer whose address is now on a forum.

For Bol specifically, this is the second customer-data scare of 2026. In April, criminal-forum listings advertised roughly 400,000 bol.com-linked customer rows; Bol said it saw no evidence of a hack, and analysts noted such listings often recycle older data. That episode is catalogued separately as a disputed claim. This one is different in kind: the retailer is not disputing anything. It named the vendor and told customers what may have been copied.

What the regulator side looks like

Both retailers reported the incident to the Autoriteit Persoonsgegevens, the Dutch Data Protection Authority — Bol because customer personal data may be involved, De Bijenkorf as a precaution. Under the GDPR that filing is due within 72 hours of becoming aware, which fits the August 3 detection and the August 5–6 notices.

Two things follow. First, the retailers here are data controllers and CEVA is a processor, so the duty to inform customers sits with Bol and De Bijenkorf even though neither was breached — which is exactly why you heard from them and not from CEVA. Second, individual notification obligations scale with confirmed scope, and scope is unresolved. Expect more precise communications, including possible follow-up messages with actual numbers, over the coming weeks rather than days.

What you should do

  1. Treat every message about a recent Bol or Bijenkorf order as hostile until proven otherwise. The attackers know what you bought. That is the whole trick.
  2. Never pay a "delivery," "customs" or "reactivation" fee from a link. Legitimate Dutch retailers do not chase €1.50 by SMS. Refuse iDEAL requests that arrive in messages.
  3. Check order status only in the official app or by typing the retailer's address yourself. No exceptions, including for messages that quote your order number correctly.
  4. Do not approve a bank-app or MFA prompt you did not personally start. If one appears during a phone call, the call is the attack.
  5. Warn the person you shipped a gift to. Their name and address may be in the exposed order record, and they have no reason to expect a scam referencing it.
  6. Turn on transaction alerts with your bank. Payment data was not part of this breach, but social-engineering-driven transfers are the realistic loss here, and alerts catch them fastest.
  7. If you reused your Bol or Bijenkorf password elsewhere, change it anyway. Credentials are not reported as exposed; password reuse is still the cheapest thing you can fix this week.
  8. Business and marketplace sellers: verify any change to payment details out of band, by calling a number you already had, not one supplied in the email.
  9. Keep the notice. If fraud follows, the dated retailer communication is what supports a complaint to your bank or the Autoriteit Persoonsgegevens.

Why "our own systems were not affected" misses the point

Bol's statement that its own systems were untouched is accurate, and it is the correct thing to tell customers. It is also, from the customer's side, almost irrelevant. Your address does not become less exposed because the copy that leaked was the vendor's copy.

The reason retailers keep ending up here is data minimisation, or the absence of it. A fulfilment centre needs a name, an address and a phone number to deliver a parcel. Whether it needs the customer's email address, or a full order history, or the same data for weeks after delivery, is a design decision — and the default in most warehouse management systems is to keep everything, in plain text, for as long as it might conceivably be useful.

That default is what converts a warehouse intrusion into a national consumer-fraud event. The attackers did not need to reach a payment processor. They reached the mundane operational database that had quietly accumulated everything needed to impersonate the retailer convincingly.

What retailers should be asking their fulfilment vendors

  • What customer fields does the vendor actually receive, and which of them can be dropped or pseudonymised? An opaque order reference plus a shipping label is often enough.
  • How long is order data retained after a parcel is delivered, and is deletion automated or aspirational?
  • How fast is the notification clock under the contract? The GDPR gives the controller 72 hours from awareness — worth nothing if the processor takes a week to say anything.
  • Is there egress monitoring on the systems holding customer data, or only endpoint antivirus on warehouse workstations?
  • Which of the vendor's other clients share the same infrastructure, and does one client's compromise expose the rest?

Those five questions are cheaper to answer before an incident than during one. Every retailer that outsources fulfilment inherits the answers whether it asks or not.

Canonical records

BreachHistory tracks this as one vendor incident with two retailer disclosures:

  • CEVA Logistics 2026 — the distribution-centre intrusion behind both notices; vendor had not issued its own statement at indexing time.
  • Bol 2026 — company-confirmed third-party breach; names, addresses, phone numbers, emails and order details; count unknown.
  • De Bijenkorf 2026 — company-confirmed logistics-partner breach; names, contact details and online-order data at risk; partner unnamed.

Sources: NL Times on Bol, NL Times on De Bijenkorf, RTL Nieuws, DataBreaches.net.

Published 2026-08-07. This record will be updated if CEVA Logistics issues a statement, either retailer publishes an affected-customer count, or a group claims the intrusion.