Thu 06 Aug 2026 / 07:34 ET
Kernel
Security 2 min read

De Bijenkorf cyber incident delays orders as data review continues

A security incident at a De Bijenkorf logistics partner has slowed deliveries and refunds while the retailer examines possible data exposure.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

De Bijenkorf cyber incident delays orders as data review continues
img: The Record

The De Bijenkorf cyber incident is slowing deliveries, returns and refunds after a security problem at an outside logistics partner. The Dutch department-store chain says its shops, website and app remain operating, and customers can still place online orders.

De Bijenkorf said Wednesday that it has no current indication its own infrastructure was compromised. The affected systems belong to the unnamed logistics provider, according to the retailer. That distinction matters, though it is not a final all-clear: an external investigation is still examining the cause, scope and consequences of the incident.

What data may be involved in the De Bijenkorf cyber incident?

De Bijenkorf is investigating whether customer information was accessed and how many people may be affected. It has not said that any customer data was taken.

The retailer said the information that may be involved includes names, email and postal addresses, phone numbers, and online-purchase records. Those order records can include products ordered, prices, discounts, delivery details and the payment method used. For business customers, company names and VAT numbers may also be affected.

De Bijenkorf said the logistics partner did not store payment-card details, bank-account numbers, usernames or passwords. On that basis, it said customer accounts are not believed to be at risk because login credentials were not part of the incident. Those statements describe what the partner held, rather than a completed finding from the investigation.

What has De Bijenkorf done and what remains unknown?

According to De Bijenkorf, the logistics provider blocked access and added security measures after discovering the problem. The retailer said it has notified customers who could be affected as a precaution and reported the incident to the Dutch data-protection authority.

  • Working: physical stores, the website and mobile app, with online orders still accepted.
  • Delayed: deliveries, returns and refunds.
  • Still under review: whether customer information was accessed, the number of affected people, and the cause of the incident.
  • Not disclosed: the logistics partner's identity, whether ransomware was involved, whether any ransom was demanded, and any responsible threat actor.

Customers awaiting an order or refund should expect a slower process, based on De Bijenkorf's notice. Because the investigation is ongoing, shoppers should independently verify unexpected messages about orders or refunds through the retailer's usual channels.

De Bijenkorf runs seven department stores in the Netherlands and online stores serving the Netherlands and Belgium, RetailDetail reported. The episode illustrates how a disruption at a logistics contractor can reach a retailer's customer operations even while the retailer's storefront systems remain available.

This story draws on original reporting from The Record.

More Security/

view all ↗