2 Remove Virus

Bol warns customers of possible data breach after cyberattack on logistics provider

Dutch online retailer Bol is dealing with delivery disruptions and a potential exposure of customer information after hackers gained access to systems operated by one of its warehouse logistics providers. Bol’s own technology infrastructure was not compromised, according to the company.

 

 

Bol learned about the security incident on August 1, when it was informed that an unauthorized party had accessed two IT systems belonging to the external provider. The affected systems contained information used to process and deliver customer orders.

The retailer responded by suspending data transfers to the logistics company while the incident was investigated. Access by the unauthorized party was blocked, and external cybersecurity specialists were brought in to determine how the intrusion occurred and establish the extent of the compromise.

The incident has already affected some customers at an operational level. Orders handled through the affected warehouse may have arrived late or been canceled as the companies responded to the attack.

More importantly, investigators determined that information required for processing those orders may have been accessed or copied. Bol is therefore treating the incident as a personal data breach and has notified the Dutch Data Protection Authority.

The potentially compromised records include customer names, delivery addresses, telephone numbers, order information and track-and-trace details. Bol said there is currently no indication that account passwords, customer login credentials or payment information were involved.

The number of people affected remains unknown. Rather than notifying its entire customer base, Bol said it has contacted customers whose information may have been present in the compromised systems.

Additional reporting has identified the affected warehouse operator as CEVA Logistics. Bol reportedly named CEVA in communications sent directly to affected customers. Dutch media have also reported that data allegedly obtained from the incident has appeared for sale on the dark web. The available information does not independently establish the contents or completeness of the dataset being advertised.

The possible exposure creates another risk even without passwords or financial information being compromised. Details about actual purchases, delivery addresses, and parcel tracking can provide useful context for convincing phishing messages. An attacker could potentially impersonate a retailer or delivery company while referring to information that makes a fraudulent communication appear legitimate.

Bol has consequently advised affected customers to be particularly cautious about unexpected emails, text messages or calls concerning their orders and deliveries.

The retailer has emphasized that the intrusion occurred outside its own IT environment. Based on its investigation so far, there is no evidence that the attackers gained access to bol’s systems.

The incident also appears to have implications beyond a single retailer. Dutch department store De Bijenkorf recently disclosed a separate potential customer data breach involving an external logistics provider. De Bijenkorf did not publicly identify that company as CEVA Logistics, so a connection between the two incidents cannot be confirmed from the companies’ public disclosures alone.

For bol, the immediate consequences involve both customer privacy and logistics. The investigation must still determine how many customers were affected, exactly what information was copied and whether the data reportedly circulating on cybercrime markets originated from the compromised warehouse systems.