Dutch department store chain De Bijenkorf has informed customers that some personal information may have been exposed following a cybersecurity incident involving one of its external logistics partners. The retailer said the breach occurred within the service provider’s IT environment and that there is currently no evidence that its own internal systems were compromised.
According to the company, the incident began after an unauthorized party gained access to parts of the logistics provider’s network. The affected partner isolated the impacted systems shortly after discovering the intrusion and has engaged an independent cybersecurity firm to determine how the attack occurred, what information may have been accessed, and the overall scope of the breach.
While the investigation remains ongoing, De Bijenkorf said preliminary findings indicate that customer information may have been copied during the incident. The data potentially involved includes customer names, postal addresses, email addresses, telephone numbers and order history records. For business customers, company names and VAT identification numbers may also have been exposed.
The retailer emphasized that the compromised information does not include payment card details, bank account information, usernames or passwords. Based on the information available so far, the company said there is no indication that financial credentials or online account authentication data were accessed.
As required under applicable privacy regulations, De Bijenkorf has reported the incident to the Dutch Data Protection Authority while the investigation continues. The company said it is working closely with the logistics provider to assess the full impact and determine whether additional notifications will be required.
Although the attack targeted an external supplier rather than De Bijenkorf’s own infrastructure, the incident has temporarily affected some operational processes. Customers may experience delays involving deliveries, returns and refunds while systems continue to be restored. The retailer said its physical stores remain open and online shopping services continue to operate.
De Bijenkorf stated that it immediately reviewed its own technology environment after learning of the incident. Based on its current assessment, the company has not identified signs that attackers gained access to its internal systems. Even so, it said monitoring and investigative work remain ongoing until the full extent of the compromise has been established.
The company is also advising customers to remain alert for phishing attempts that may take advantage of the incident. Criminals frequently use information obtained during data breaches to send convincing emails, text messages or telephone calls impersonating legitimate businesses. De Bijenkorf said customers should avoid sharing passwords, payment details or other sensitive information in response to unsolicited communications, even if they appear to reference recent purchases or account activity.