De Bijenkorf, the Dutch department-store chain, has confirmed that unauthorised parties gained access to its customers' personal data during a security breach at its logistics partner CEVA Logistics in early August. The admission, published on 11 September, ends weeks of speculation and reveals that the same intrusion exposed data belonging to customers of four other major organisations: online retailer Bol, eyewear brand Ace & Tate, fashion platform Zalando and banking group ING.

What the investigation found

According to De Bijenkorf, CEVA's internal investigation established that unknown actors accessed systems containing customer information. The logistics provider handles warehousing, fulfilment and returns for multiple retailers, meaning a single compromise can fan out across brands. De Bijenkorf said it was informed of the confirmed access only recently, having previously been told the incident was under investigation but not yet verified.

The retailer did not specify how many of its customers are affected, nor what categories of data, names, addresses, payment details, order histories, were exposed. Bol, Ace & Tate, Zalando and ING have each acknowledged the breach in separate statements, though the extent varies. ING said the compromised data related to a specific logistics process and did not include core banking credentials or transaction records.

Supply-chain risk made real

The incident illustrates a structural weakness in European retail and finance: the concentration of customer data in third-party logistics operators that fall outside direct regulatory scrutiny. CEVA, a subsidiary of the CMA CGM Group, operates across the continent. A breach at one of its Dutch facilities has therefore triggered notifications in multiple jurisdictions under the General Data Protection Regulation (GDPR).

Under GDPR Article 33, data controllers must notify the relevant supervisory authority within 72 hours of becoming aware of a breach. De Bijenkorf, Bol, Ace & Tate, Zalando and ING are each controllers for their own customer data; CEVA acts as a processor. The Dutch authority, Autoriteit Persoonsgegevens (AP), confirmed it has received notifications and is assessing whether security measures were adequate.

Regulatory scrutiny intensifies

The AP has fined organisations for supply-chain failures before. In 2023 it levied a €3.7 million penalty against a telecommunications provider after a breach at a marketing subcontractor exposed subscriber data. The regulator has signalled that it will examine whether the affected companies conducted proper due diligence on CEVA's security posture and whether contractual safeguards, mandatory under GDPR Article 28, were enforced.

A spokesperson for the AP said the authority is "investigating the circumstances and the measures taken by both the controllers and the processor". The investigation could result in fines of up to 4% of global annual turnover for each controller found negligent, though in practice Dutch fines have ranged from tens of thousands to low single-digit millions.

CEVA's position and response

CEVA Logistics issued a brief statement acknowledging the intrusion and saying it had "contained the incident, engaged external forensic experts and notified all affected clients". The company did not disclose the attack vector, whether ransomware, credential theft, vulnerability exploitation or insider action, nor whether data was exfiltrated or merely accessed. It said it is "implementing additional security controls" across its European network.

Logistics providers have become attractive targets. In 2024 a ransomware attack on a major European freight forwarder disrupted customs clearance for weeks. In 2025 a breach at a UK-based fulfilment centre exposed order data for dozens of fashion brands. The sector's mix of legacy operational technology, fragmented IT estates and high-value personal data makes it a persistent weak link.

Differing exposure across the five brands

The five affected organisations face different risk profiles. Bol, the Netherlands' largest online retailer, holds address, payment and purchase history for millions of Dutch and Belgian consumers. Zalando, operating across 25 European markets, processes returns and fulfilment through multiple logistics partners; the CEVA breach appears limited to its Benelux operations. Ace & Tate, a smaller direct-to-consumer eyewear brand, relies heavily on CEVA for European distribution.

ING's exposure is narrower. The bank said the compromised data related to a specific logistics service, understood to be physical document handling for mortgage and loan paperwork, and that no authentication credentials, account numbers or transaction data were involved. Nevertheless, under GDPR even limited personal data triggers notification obligations.

Customer communication and next steps

De Bijenkorf said it is contacting affected customers directly and offering guidance on phishing vigilance, password hygiene and credit monitoring. Bol and Zalando have published help-centre articles. Ace & Tate said it would email customers whose data was in the affected CEVA systems. ING has written to the relevant mortgage and loan customers.

None of the five organisations has offered free credit-monitoring subscriptions, a practice common in US breaches but rare in Europe. The AP does not require it, though it may recommend it where identity-theft risk is high. Consumer group Consumentenbond has called for a coordinated response and clearer timelines.

Broader implications for European retail

The breach arrives as the European Commission prepares to adopt the Cyber Resilience Act, which will impose mandatory security requirements on products with digital elements, including logistics tracking hardware and warehouse management software. It also coincides with the transposition deadline for the NIS2 Directive, which expands mandatory incident reporting to large logistics providers classified as essential entities.

Industry analysts say the case will accelerate contractual renegotiation between retailers and logistics partners. "Controllers are realising they cannot outsource accountability," said a privacy lawyer at a major Amsterdam firm who advises on GDPR compliance. "Expect more audits, more penetration-test clauses and more liability caps in processor agreements."

Organisations

De Bijenkorf · CEVA Logistics · Bol · Ace & Tate · Zalando · ING