2026 CEVA Logistics — distribution-centre intrusion behind Bol and De Bijenkorf customer-data warnings (Aug)
Data compromised
Order-handling data for recent orders processed through the affected distribution centre. For Bol customers: names, street addresses, postal codes, cities, phone numbers, email addresses and order details. For De Bijenkorf customers: names, contact details and online-order data. Both retailers state no payment data, bank account numbers, passwords or account login credentials were involved. RTL Nieuws reported leaked Bol and De Bijenkorf customer data offered for sale on a dark-web forum.
Technical writeup
Root cause
Unauthorised parties accessed systems at the logistics partner handling e-commerce order processing and delivery for Dutch retailers; the partner blocked access, isolated systems and added security measures after detection on the morning of August 3, 2026. Named as CEVA Logistics in the notice Bol sent to potentially affected customers; CEVA had not published its own statement at indexing time.
References
- https://nltimes.nl/2026/08/06/bol-follows-de-bijenkorf-warning-data-breach-leaked-data-appears-dark-web
- https://nltimes.nl/2026/08/05/de-bijenkorf-warns-customers-possible-data-breach-logistics-partner
- https://www.rtl.nl/nieuws/economie/artikel/5635920/gegevens-bol-en-bijenkorfklanten-de-uitverkoop-op-darkweb
- https://databreaches.net/2026/08/06/dutch-retailer-bol-follows-de-bijenkorf-in-warning-of-data-breach-as-leaked-data-appears-on-dark-web/