De Bijenkorf Alerts Customers to Potential Data Exposure Following Cyber Attack

0
5

Key Takeaways

  • De Bijenkorf experienced a cyberattack on an external logistics partner, delaying orders, returns, and refunds while potentially exposing personal data.
  • The retailer confirmed its own systems were not compromised; stores, website, and mobile app remain operational.
  • Exposed data may include names, email, postal addresses, phone numbers, purchase details, and for business customers, company names and VAT numbers—payment card details and login credentials were not stored by the logistics provider.
  • De Bijenkorf has notified potentially affected customers and reported the incident to the Dutch data protection authority; an investigation is ongoing to determine the scope of any data breach.
  • The attack is part of a broader trend where cybercriminals target retailers indirectly through third‑party service providers, as seen in recent incidents affecting Żabka, Lidl, and major logistics firms in Japan and Europe.
  • No ransomware claim or public attribution has been made for the De Bijenkorf logistics breach at this time.

Incident Overview
On Wednesday, Amsterdam‑based luxury department store chain De Bijenkorf disclosed that a cyberattack had compromised the systems of one of its external logistics providers. The breach did not affect De Bijenkorf’s internal infrastructure; the retailer emphasized that its physical stores, e‑commerce website, and mobile application continue to function normally. However, the disruption to the logistics partner’s operations has led to noticeable delays in order fulfillment, returns processing, and refund issuance for online customers.

Impact on Customers
De Bijenkorf advised that shoppers can still place online orders, but delivery times are longer than usual. Returns and refunds are likewise being handled more slowly while the logistics partner works to restore normal service levels. The retailer has not disclosed the exact number of orders affected, but the slowdown is expected to persist until the partner’s systems are fully secured and operational again.

Data Potentially Exposed
According to the retailer, the compromised logistics system may have exposed personal information such as names, email addresses, postal addresses, phone numbers, and details related to online purchases—including ordered products, prices, discounts, delivery information, and the payment method used. For business‑to‑business transactions, company names and VAT numbers could also have been accessed. Importantly, the logistics provider does not store payment card numbers, bank account details, usernames, or passwords, so those specific data elements are unlikely to have been compromised. Customer accounts themselves are not considered at risk because no login credentials were involved in the breach.

Response and Notification
As a precautionary measure, De Bijenkorf has notified potentially affected customers about the incident and reported it to the Dutch data protection authority (Autoriteit Persoonsgegevens). The company stated that an investigation is underway to determine whether any customer data was actually accessed and, if so, how many individuals were impacted. No timeline for the completion of the investigation has been provided, but De Bijenkorf promised to share further updates as they become available.

Operational Continuity
Despite the logistics disruption, De Bijenkorf confirmed that its own IT environment shows no signs of compromise. The retailer’s internal networks, point‑of‑sale systems in its seven Dutch department stores, and online channels remain secure and fully functional. This separation helped limit the breach’s fallout to the supply‑chain layer rather than the core retail operations.

Broader Trend of Supply‑Chain Attacks
The De Bijenkorf incident exemplifies a growing pattern in which cybercriminals target retailers indirectly by compromising third‑party vendors and service providers. Earlier this week, Polish convenience‑store chain Żabka reported unauthorized access to its internal systems after attackers allegedly breached an account belonging to an external service provider. Żabka noted that customer‑facing services and payment systems remained unaffected.

Recent Comparable Incidents
In July, discount supermarket operator Lidl disclosed that customer information from its online stores in Germany, Belgium, and the Netherlands was exposed after attackers infiltrated one of its IT service providers. The same month, a ransomware attack on Japan’s largest refrigerated logistics company disrupted food deliveries nationwide, causing supply shortages for restaurant chains such as Kentucky Fried Chicken and illustrating how a breach at a logistics provider can cascade through retail supply chains. Additionally, luxury goods retailers Harrods and Louis Vuitton reported cybersecurity incidents in 2025, further underscoring the sector’s vulnerability.

Why Attackers Focus on Logistics and Service Providers
Cybercriminals often favor supply‑chain targets because they can yield access to multiple downstream organizations with a single point of entry. Logistics providers typically handle vast amounts of personal and transactional data while maintaining fewer defensive resources than large retailers, making them attractive footholds. Once inside, attackers can exfiltrate data, deploy ransomware, or manipulate operations to create financial pressure on the victim companies.

Mitigation and Future Outlook
De Bijenkorf’s response—prompt containment by the logistics partner, communication with regulators, and customer notifications—aligns with recommended incident‑handling practices. However, the episode highlights the need for retailers to enforce stringent security requirements on their third‑party contracts, conduct regular vendor risk assessments, and implement robust monitoring for anomalous activity across supply‑chain networks. As cyber threats continue to evolve, collaborative defense strategies that combine retailer vigilance with provider hardening will be essential to safeguard both operational continuity and customer data.


Word count: approximately 945 words.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here