Infosecurity

De Bijenkorf warns of possible customer data exposure after logistics partner cyberattack

Published

on

What happened at De Bijenkorf?

Dutch luxury department store chain De Bijenkorf has warned that customer data may have been exposed after a cyberattack hit one of its logistics providers. The incident, disclosed Wednesday, has thrown a wrench into the retailer’s operations — deliveries are dragging, returns are stuck, and refunds are moving at a snail’s pace.

The Amsterdam-based company was quick to clarify that its own systems were not breached. The attack targeted only the infrastructure of an external logistics partner. “Our logistics partner intervened immediately, blocked access, and took additional security measures,” De Bijenkorf said in a statement. Stores, the website, and the mobile app remain fully operational.

Still, the fallout is real. Customers can place online orders, but they shouldn’t expect speedy delivery. The company is also processing returns and refunds slower than usual while the investigation grinds on.

What customer data could be exposed?

The investigation is still in its early stages, and De Bijenkorf hasn’t confirmed whether any data was actually accessed — or how many people might be affected. But the potential scope is unsettling.

The logistics provider may have held names, email addresses, postal addresses, phone numbers, and details tied to online purchases. That includes ordered products, prices, discounts, delivery information, and the payment method used. For business customers, company names and VAT numbers could also be in the mix.

Here’s the silver lining: no payment card details, bank account numbers, usernames, or passwords were stored by the logistics partner. So those sensitive pieces of data are likely safe. Customer accounts are also not believed to be at risk, since no login credentials were involved.

De Bijenkorf has already notified potentially affected customers as a precaution and reported the incident to the Dutch data protection authority. The company hasn’t said whether ransomware was involved or if a ransom demand was made. No threat actor has publicly claimed responsibility.

A growing pattern: attackers go after the weak link

This isn’t an isolated event. Cybercriminals are increasingly targeting retail giants indirectly — by compromising their suppliers and service providers instead of going head-to-head with hardened corporate defenses.

Earlier this week, Polish convenience store behemoth Żabka disclosed unauthorized access to its internal systems after attackers allegedly compromised an account belonging to an external service provider. The company said customer-facing services and payment systems were unaffected.

In July, discount supermarket operator Lidl reported that customer information from its online stores in Germany, Belgium, and the Netherlands was exposed after attackers breached one of its IT service providers.

The pattern is clear. Attackers find the soft underbelly — a third-party vendor with weaker security — and use it as a gateway to reach the bigger prize.

Logistics attacks ripple through the supply chain

The damage isn’t always limited to data. In July, a ransomware attack on Japan’s largest refrigerated logistics company disrupted food deliveries nationwide. Restaurant chains, including Kentucky Fried Chicken, faced supply shortages. It was a stark reminder of how an attack on a single logistics provider can send shockwaves through the entire retail supply chain.

The luxury sector has also felt the heat. Both Harrods and Louis Vuitton reported cybersecurity incidents in 2025. These are brands with massive security budgets — yet they still got hit, often through third parties.

What should De Bijenkorf customers do now?

If you’re a De Bijenkorf customer, here are a few practical steps to consider while the investigation unfolds:

  • Watch your inbox for official notifications from the retailer — they’ll tell you if your data was likely affected.
  • Be extra cautious with unsolicited emails or calls claiming to be from De Bijenkorf. Phishing attempts often spike after breaches like this.
  • Monitor your bank statements and online accounts for any unusual activity, even though payment details weren’t stored by the logistics provider.
  • If you’re a business customer, keep an eye on your VAT records and company information.

De Bijenkorf operates seven department stores in the Netherlands and employs roughly 4,500 people. The company has promised to keep customers updated as the investigation progresses.

This incident is another reminder that in today’s interconnected retail ecosystem, your security is only as strong as your weakest vendor. For more on how third-party risks are shaping the threat landscape, check out our coverage of supply chain cyberattacks in retail and how logistics providers become prime targets for ransomware gangs.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version