← CEVA Logistics

2026 CEVA Logistics — distribution-centre intrusion behind Bol and De Bijenkorf customer-data warnings (Aug)

2026 Unknown records affected Share on X

Data compromised

Order-handling data for recent orders processed through the affected distribution centre. For Bol customers: names, street addresses, postal codes, cities, phone numbers, email addresses and order details. For De Bijenkorf customers: names, contact details and online-order data. Both retailers state no payment data, bank account numbers, passwords or account login credentials were involved. RTL Nieuws reported leaked Bol and De Bijenkorf customer data offered for sale on a dark-web forum.

Technical writeup

Third-party breach confirmed by the affected retailers, not yet by the vendor — De Bijenkorf said the security breach was officially detected on the morning of Monday, August 3, 2026 at a logistics partner that handles logistics "in the broadest sense of the word" (explicitly not a parcel carrier such as PostNL or DHL), and warned customers on August 5 that names, contact details and online-order data could not be ruled out as exposed. Bol followed on August 6 and named the partner: CEVA Logistics, which processes and delivers orders from one of Bol distribution centres. Bol said its own systems were not affected, that the partner cut off unauthorised access immediately and introduced additional measures, and that it cannot yet determine how many customers are involved because exposure is limited to order data held in the affected CEVA system. Both retailers notified the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and both report operational fallout: Bol pulled products stored at the affected facility from sale and cancelled or delayed orders, while De Bijenkorf reported delays in orders, returns and refunds after the partner shut down specific data systems to contain the intrusion. RTL Nieuws subsequently reported that data on Bol and De Bijenkorf customers is being offered on the dark web. No ransomware group had publicly claimed the intrusion at indexing time, and no attested record count exists yet, so recordsAffected is 0 pending a count from CEVA, the retailers or the regulator.

Root cause

Unauthorised parties accessed systems at the logistics partner handling e-commerce order processing and delivery for Dutch retailers; the partner blocked access, isolated systems and added security measures after detection on the morning of August 3, 2026. Named as CEVA Logistics in the notice Bol sent to potentially affected customers; CEVA had not published its own statement at indexing time.

References