De Bijenkorf, a prominent Dutch luxury department store, has encountered delays in customer orders, returns, and refunds due to a cyberattack on one of its logistics providers. This incident may have potentially exposed customer data. The retailer, based in Amsterdam, confirmed that only the systems of the external logistics partner were affected, and there is currently no indication of any compromise to De Bijenkorf’s own infrastructure. In response to the breach, the logistics partner promptly intervened, blocked access, and implemented additional security measures to prevent further damage. Despite the breach, De Bijenkorf’s stores, website, and mobile app continue to operate, although delivery times have been extended and returns and refunds are being processed at a slower pace.

The investigation is ongoing to ascertain whether customer information was accessed and to identify the number of affected individuals. The potentially compromised data includes personal details such as names, email addresses, postal addresses, phone numbers, and information related to online purchases. However, payment card details, bank account numbers, usernames, and passwords were not stored by the logistics provider, mitigating some risk of financial data exposure.

As a precautionary measure, De Bijenkorf has informed potentially affected customers and reported the incident to the Dutch data protection authority. It remains unclear whether ransomware was involved or if a ransom demand was made, and no threat actor has taken responsibility for the attack. This incident highlights a growing trend where cybercriminals target retail chains by compromising their suppliers and service providers. Recent similar incidents have affected other companies, including Żabka in Poland and Lidl in Germany, Belgium, and the Netherlands, underscoring the need for robust security measures across supply chains.