A cyber intrusion at eight European warehouses run by logistics giant Ceva has delayed shipments and put customer information at risk for two major Dutch retailers.

A cyberattack struck eight European warehouses operated by Ceva Logistics over the weekend of Aug. 1, disrupting order processing for retail customers and exposing personal data belonging to shoppers at Dutch e-commerce company bol and department store chain De Bijenkorf.
Ceva, a third-party logistics provider with more than 1,000 warehouses worldwide and $18.3 billion in revenue last year, notified affected customers of the intrusion on Aug. 1. The breach was confined to the eight warehouses and did not touch the company’s broader operations; air, ocean, ground and rail transportation management services continued without interruption. Ceva has issued no public statement on the incident, which is now under investigation by the Dutch Data Protection Authority along with other law enforcement agencies and the businesses involved.
Bol and De Bijenkorf informed customers Wednesday that unauthorized parties had breached information technology systems belonging to their logistics partner, exposing personal details though not credit card or payment information. Bol said the breach involved two systems used to process orders from one of its distribution centers and that its own systems were not compromised. The company said customer data handled at that location may have been viewed or copied, and it has suspended all data exchanges with the logistics partner as a precaution until safety can be confirmed. Products stored at the affected site have been taken offline, and some orders have been canceled or delayed.
De Bijenkorf told customers that order processing, returns and refunds could take longer than usual, though its stores and online ordering remain open.
Dutch broadcaster NOS reported that names, addresses, postcodes and phone numbers may have been among the data accessed. Neither retailer has disclosed how many customers were affected. De Bijenkorf has commissioned an external investigation and said it blocked access to the compromised systems and added additional security measures. The company said it was confident that bank account numbers and passwords were not exposed, and that email addresses and product information may also have been taken.
Bol said there is no indication that payment details, passwords or login credentials were compromised.
Ceva informed bol of the possible breach on Aug. 1, and the Dutch Data Protection Authority was notified Aug. 3, though customers were not emailed until Wednesday. A bol spokesperson told NOS the company first wanted to determine the scope of the incident and who was affected before reaching out, rather than contacting customers multiple times.
Neither retailer has publicly named Ceva as the source of the breach in its own communications, though the identity of the logistics provider has since become known. Ceva also processes orders for other retailers, and it remains unclear whether their customers have been affected. Some applications and services at the affected distribution centers have since been restored for certain customers.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543