Logistics partner hack disrupts Dutch retailer’s business operations, customer information possibly exposed
A third-party hack has hit online retail giant bol.

- A cyberattack on bol’s logistics partner CEVA Logistics disrupted order processing and may have exposed customer data.
- bol said its own IT systems were not affected and suspended data exchanges with the partner after the incident.
- Potentially exposed data includes names, addresses, phone numbers, delivery tracking information, and order details.
- bol reported the breach to Dutch regulators and warned affected customers to watch for phishing and fraud attempts.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
One of bol’s warehousing logistics partners has fallen victim to a cyberattack, affecting the online retailer’s day-to-day business operations. Customer data may have also been stolen or copied.
On August 1st, bol was informed that one of its warehousing logistics partners had been involved in a “cyber incident.” An unauthorized party managed to gain access to 2 of its IT systems and the data stored there.
Upon discovery, the attacker was locked out of the system, and external cybersecurity specialists launched an investigation into the incident. As a precaution, bol immediately suspended all data exchanges with this partner.
According to a press release, no IT systems of bol were affected by the incident.
“Because unauthorized parties may have had access to customers’ personal data, we are treating this incident as a data breach,” the largest online retail platform in the Netherlands said in a public statement.
For that reason, bol has reported the incident to the Dutch data protection authority.
The data that has potentially been exposed includes names, physical addresses, phone numbers, track-and-trace information, and order details. There’s no indication that payment details, passwords, or customer login credentials were involved in the incident.
As of writing, bol can’t provide any information about the exact number of affected customers. Customers whose data may have been involved have been informed directly.
“Orders processed through the affected location may experience delays or have been canceled. In addition, personal data required for processing and delivering orders may have been viewed or copied by unauthorized parties,”bol states.
Therefore, affected customers are advised to remain alert to phishing attempts and other types of fraud.
In an email to affected customers, bol says that the security incident happened at CEVA Logistics. According to Dutch news outlet RTL Nieuws, the exfiltrated customer data is currently being offered for sale on the dark web.
On Wednesday, Dutch department store De Bijenkorf warned customers about a potential data breach due to an incident at an external logistics partner. The company never mentioned CEVA Logistics as the source of the breach.