Decoding the world of cybersecurity

Logistics breach stalls De Bijenkorf orders

Unauthorised access at a De Bijenkorf logistics provider has delayed orders, returns, and refunds, with customer contact and purchase information potentially exposed.

Logistics breach stalls De Bijenkorf orders
Summary
  • Attackers accessed systems belonging to an external logistics provider rather than De Bijenkorf’s own infrastructure.
  • Order processing, returns, refunds, and tracking have been delayed, although shops and online ordering remain available.
  • Contact, purchase, delivery, and some business-customer data may be involved; passwords and financial credentials were excluded.

A security incident at a logistics provider used by De Bijenkorf has delayed orders, returns, refunds, and tracking while investigators assess the possible exposure of customer information.

The Dutch department-store group said unauthorised parties accessed part of the provider’s systems. The supplier blocked the access and introduced additional security measures, while an external organisation investigates the cause, scope, and consequences.

De Bijenkorf said it had found no indication that its own systems were compromised. Its seven shops remain open, and customers can continue to place orders through its website and mobile application. The disruption sits behind those services, where the logistics provider processes fulfilment and returns.

Customers have been warned that deliveries may take longer than expected, track-and-trace information may be inaccurate, and returns and refunds may face delays. De Bijenkorf has not provided a timetable for clearing the accumulated backlog.

The retailer has also identified the information that may have been held in the affected systems. It includes names, email addresses, postal addresses, telephone numbers, and details of online orders, such as products, prices, discounts, delivery information, and a description of the payment method used.

Business-customer records may additionally include company names and value-added tax numbers entered into customer accounts. De Bijenkorf noted that some older VAT identifiers used by sole traders may have been derived from Dutch citizen-service numbers, increasing the potential sensitivity of those records.

The supplier did not hold card details, bank-account numbers, usernames, or passwords in the affected environment. A record showing whether a customer paid by card or another method may be present, but the underlying financial credentials were not included, according to the retailer.

Investigators have not yet established whether the attacker accessed or copied the potentially affected information, or how many customers are involved. De Bijenkorf has informed customers as a precaution and reported the incident to the Dutch Data Protection Authority.

The operational disruption shows how a compromise outside a retailer’s own network can affect the service it remains responsible for delivering. Ecommerce fulfilment depends on information moving between storefronts, warehouses, couriers, returns systems, customer-service tools, and payment processes. The outage of one connected operator can interrupt the transaction after an order has apparently completed successfully.

Returns and refunds create particular recovery pressure. Delayed reimbursements affect customers directly, while unprocessed goods create inventory, reconciliation, and accounting work. Restored systems must be matched against parcels already moving through warehouses and delivery networks, rather than simply switched back on.

The incident also tests contractual and regulatory responsibilities between the retailer and its provider. The supplier operates the affected infrastructure, but De Bijenkorf remains the organisation with the customer relationship and is communicating with affected individuals and the regulator.

The confirmed impact is currently operational delay and unauthorised access at the logistics provider. The number of people affected, whether data was extracted, and the initial access route remain unknown.

×