← Bol (bol.com)

2026 Bol — CEVA Logistics partner breach; customer names, addresses, phones and order details exposed (Aug 6)

2026 Unknown records affected Share on X

Data compromised

Names, street addresses, postal codes, places of residence, phone numbers, email addresses and order details for recent orders handled by the affected distribution centre. Bol says it has found no evidence that payment data, passwords or account login credentials were exposed.

Technical writeup

Company-confirmed third-party breach — on August 6, 2026 Bol, the largest online retailer in the Netherlands and Belgium, told customers that unauthorised parties had accessed systems at one of its logistics partners and that some customer information may have been viewed or copied. Bol named the partner as CEVA Logistics, responsible for processing and delivering orders from one of its distribution centres, and said the partner acted immediately on detection by cutting off access and adding security measures. Exposure is limited to data held in the affected CEVA system for recent orders processed through that centre: names, addresses, postal codes, places of residence, phone numbers, email addresses and order details. Bol says it found no evidence that payment data, passwords or account credentials were involved, and reported the incident to the Dutch Data Protection Authority because personal data may be affected. The company said it cannot yet determine how many customers are involved, so recordsAffected is 0 pending an attested figure. Operationally, products stored at the affected facility were pulled from sale and some orders were cancelled or delayed. Bol advised customers to be extra alert for phishing and fraud — advice sharpened the same day when RTL Nieuws reported that Bol and De Bijenkorf customer data was being offered for sale on the dark web. Earlier in the day De Bijenkorf had issued a similar warning about a logistics partner it declined to name.

Root cause

Breach at logistics partner CEVA Logistics, which processes and delivers orders from one of Bol distribution centres; unauthorised parties accessed the partner systems. Bol states its own systems were not affected.

References