De Bijenkorf Hit by Third-Party Cyberattack, Customer Data Potentially Exposed
Luxury Dutch department store chain **De Bijenkorf** has announced a cyberattack on one of its logistics providers, leading to significant delays in customer orders, returns, and refunds. The incident also carries the risk of exposing sensitive customer data, underscoring the escalating threat of supply chain attacks targeting the retail sector.
A recent cyberattack on a third-party logistics provider serving **De Bijenkorf** has disrupted operations and potentially compromised customer information. The incident, disclosed by the Amsterdam-based retailer on Wednesday, highlights a growing trend of cybercriminals targeting retail companies indirectly through their service providers.
**De Bijenkorf** confirmed that its own infrastructure was not compromised, with the attack confined to its external logistics partner's systems. "Our logistics partner intervened immediately, blocked access, and took additional security measures," the company stated, reassuring customers that its stores, website, and mobile app remain fully operational.
### Operational Disruptions and Data Risks
While customers can still place online orders, **De Bijenkorf** has advised that deliveries, returns, and refunds are experiencing longer processing times. An ongoing investigation aims to ascertain the full extent of customer data access and the number of individuals affected.
Potentially exposed information includes names, email addresses, postal addresses, phone numbers, and details related to online purchases, such as products ordered, prices, discounts, delivery information, and the payment method used. For business customers, company names and VAT numbers may also be at risk.
Crucially, the retailer emphasized that the logistics provider does not store payment card details, bank account numbers, usernames, or passwords. Therefore, these critical data points are unlikely to have been compromised, and customer accounts are not believed to be at risk.
As a precautionary measure, **De Bijenkorf** has notified potentially affected customers and reported the incident to the Dutch data protection authority. The company has not disclosed whether the attack involved ransomware or if a ransom demand was made, and no threat actor has publicly claimed responsibility.
### The Rise of Supply Chain Attacks in Retail
This incident is not isolated. Cybercriminals are increasingly exploiting vulnerabilities within the supply chains of retail and food companies, bypassing direct attacks on the larger organizations themselves. This strategy proves effective as third-party vendors often have less robust security postures than their enterprise clients.
Earlier this week, Polish convenience store giant **Ε»abka** disclosed unauthorized access to its internal systems, allegedly via a compromised account belonging to an external service provider. Similarly, in July, discount supermarket operator **Lidl** reported a data breach affecting customer information from its online stores in Germany, Belgium, and the Netherlands, also stemming from a compromised IT service provider.
Further illustrating the ripple effect of such attacks, a ransomware incident on Japan's largest refrigerated logistics company in July disrupted food deliveries nationwide, causing supply shortages for major restaurant chains, including **Kentucky Fried Chicken**. The incidents involving **Harrods** and **Louis Vuitton** in 2025 further underscore the pervasive nature of these supply chain vulnerabilities across the luxury retail sector.
These repeated attacks highlight the critical need for robust third-party risk management and comprehensive cybersecurity strategies that extend beyond an organization's immediate perimeter to encompass its entire vendor ecosystem.