De Bijenkorf's Amsterdam store
De Bijenkorf's Amsterdam store. Image: De Bijenkorf

Dutch retailer De Bijenkorf warns customer data may be exposed after cyber incident

A cyberattack on one of the logistics providers serving Dutch luxury department store chain De Bijenkorf has delayed customer orders, returns, and refunds while potentially exposing customer data.

The incident is one of several in recent months that has disrupted retail and food companies through third-party contractors.

The Amsterdam-based retailer said Wednesday that the incident affected only the systems of an external logistics partner and that there is currently no indication its own infrastructure was compromised. 

“Our logistics partner intervened immediately, blocked access, and took additional security measures,”  De Bijenkorf said, adding that its stores, website, and mobile app remain operational.

According to the company, customers can continue placing online orders, but deliveries are taking longer than usual, while returns and refunds are also being processed more slowly.

De Bijenkorf said an investigation is underway to determine whether customer information was accessed and, if so, how many people were affected. The company operates seven department stores in the Netherlands and employs about 4,500 people.

The potentially exposed information includes names, email addresses, postal addresses, phone numbers, and details related to online purchases, including ordered products, prices, discounts, delivery information, and the payment method used. For business customers, company names and VAT numbers may also have been affected.

The retailer said the logistics provider did not store payment card details, bank account numbers, usernames or passwords, so those data were likely not exposed. Customer accounts are also not believed to be at risk because no login credentials were involved in the breach.

As a precaution, De Bijenkorf said it has notified potentially affected customers and reported the incident to the Dutch data protection authority. The company did not say whether the incident involved ransomware or whether it had received a ransom demand. No threat actor has publicly claimed responsibility.

Attractive targets

Cybercriminals are repeatedly targeting retail chains indirectly by compromising suppliers and service providers rather than the retailers themselves.

Earlier this week, Polish convenience store giant Żabka disclosed unauthorized access to internal systems after attackers allegedly compromised an account belonging to an external service provider. The company said customer-facing services and payment systems were unaffected.

In July, discount supermarket operator Lidl said customer information from its online stores in Germany, Belgium, and the Netherlands was exposed after attackers breached one of its IT service providers.

That same month, a ransomware attack on Japan's largest refrigerated logistics company disrupted food deliveries nationwide, causing supply shortages for restaurant chains, including Kentucky Fried Chicken, and illustrating how attacks on logistics providers can quickly ripple through retail supply chains.

Two luxury goods retailers — Harrods and Louis Vuitton — reported cybersecurity incidents in 2025.

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.