Data Breach Hits Bol.com, ING, Ajax and de Bijenkorf
The brands themselves were not hacked. The incident involved systems operated by logistics partners, and not every customer was affected.
The brands themselves were not hacked. The incident involved systems operated by logistics partners, and not every customer was affected.
Bol.com, ING, Ajax and de Bijenkorf have reported disruption or possible customer-data exposure following security incidents at third-party logistics operations.
The companies’ own systems were not the source of the breach. At Bol.com, the exposure was limited to two systems processing orders from one distribution centre. At ING, the possible impact concerns customers who ordered physical products for home delivery through ING Points.
Bol has now identified the attacked logistics provider as CEVA Logistics in a notification sent directly to affected customers. Ajax also named CEVA as its affected partner. ING and de Bijenkorf referred to logistics partners without publicly identifying them.
Bol email confirms CEVA and limits the scope
Bol said it was informed about the incident on 1 August. In a customer notification reviewed by Daily Dutch News, Bol identifies CEVA Logistics as the partner and describes the incident as a cyberattack on CEVA’s systems.
The notification says cybercriminals gained access to CEVA systems and data. Recipients received the email because their information was stored in an affected CEVA system at the time of the attack and may have been viewed or copied.
The incident concerns two systems used to process orders from a single Bol.com distribution centre. It did not affect the retailer’s entire distribution network or every Bol.com customer.
Potentially exposed information includes names, addresses, postcodes, places of residence, email addresses, telephone numbers, gift-card messages where applicable, order numbers, EAN product codes, tracking information and order details.
Bol told recipients that the notification concerns only data connected to recent orders processed through the affected distribution centre. The email identifies at the bottom which orders may be involved for that customer.
Bol said the logistics partner did not hold customers’ passwords, bank account numbers or payment information.
CEVA took steps to stop the unauthorised access and brought in external cybersecurity specialists to investigate the cause and impact. Bol stopped exchanging data with CEVA and said the connection would remain suspended until it is considered safe. Bol notified the Dutch Data Protection Authority on 3 August and contacted customers known to be potentially affected on 5 August.
Some products stored at the location were taken offline, while certain orders were delayed or cancelled. Bol’s other distribution locations remain operational.
ING Points physical orders are in scope
ING confirmed that the incident also affects its ING Points rewards shop. The logistics partner involved stores and delivers some of the physical products offered through the programme.
Customers who ordered a physical product for home delivery may have had their names, addresses, telephone numbers, email addresses and order information exposed.
Digital products are outside the scope of the incident. This includes vouchers, gift cards, discount codes and e-tickets.
ING said its own systems were not affected. Bank accounts, savings, payment information, other financial data and login credentials were not involved.
The bank stopped exchanging data with the logistics partner and reported the incident to the Dutch Data Protection Authority. Orders placed between 1 and 5 August that would have been processed by the affected partner were cancelled. ING said customers would receive an email and have both their purchase amount and ING Points returned within ten working days.
De Bijenkorf investigates possible exposure
De Bijenkorf also reported unauthorised access to part of a logistics partner’s systems.
Potentially involved information includes names, addresses, email addresses and telephone numbers, alongside online-order data such as products, prices, discounts and delivery information. Business customer records may also contain company names and VAT numbers.
The retailer said payment information, IBANs, credit card details, usernames and passwords were not exposed.
Orders, returns and refunds may be delayed while the investigation continues. De Bijenkorf has cautioned that customers who have not received an email should not yet assume they are unaffected, as the full scope has not been established.
Ajax identifies CEVA Logistics
Ajax named CEVA Logistics as its affected partner. CEVA processes and ships orders placed through the club’s online store.
Ajax said its own systems were not affected and suspended its data exchange with CEVA. The club also reported the incident to the Dutch Data Protection Authority.
It is not yet clear whether Ajax customers’ personal information was accessed. Orders and returns from the Ajax web shop may face delays during the investigation.
The full scope remains unclear
None of the company statements explains how the attackers entered the logistics systems, whether ransomware was involved or how many people may ultimately be affected.
What the disclosures do show is that a retailer’s own website does not need to be hacked for customer information and order operations to be exposed. A breach deeper inside the logistics chain can affect several familiar Dutch brands while leaving their own platforms untouched.
Bol advised recipients to check the sender of messages, verify account numbers before transferring money and avoid links or attachments from unknown senders. Its official phishing guidance lists trusted Bol email domains and recommends opening the app or typing bol.com directly instead of following a suspicious link.