De Bijenkorf: Customer Data Potentially Exposed After Logistics Cyberattack

Published:

spot_img

De Bijenkorf: Customer Data Potentially Exposed After Logistics Cyberattack. A cyberattack targeting a logistics provider for the Dutch luxury department store chain De Bijenkorf has resulted in delays for customer orders, returns, and refunds, while also raising concerns about the potential exposure of customer data. The retailer announced that the incident affected only the systems of an external logistics partner, with no indication that its own infrastructure was compromised. This incident highlights a growing trend where cybercriminals target retail chains indirectly through third-party contractors.

De Bijenkorf’s Response to the Incident

De Bijenkorf confirmed that its logistics partner acted swiftly to block access and implement additional security measures. The retailer reassured customers that its stores, website, and mobile app remain operational, although online order deliveries are experiencing delays. The company is currently investigating whether any customer information was accessed during the breach.

The retailer operates seven department stores in the Netherlands and employs around 4,500 people. It has notified potentially affected customers and reported the incident to the Dutch data protection authority as a precautionary measure.

Details of Potentially Exposed Customer Information

The potentially exposed data includes names, email addresses, postal addresses, phone numbers, and details related to online purchases, such as ordered products, prices, discounts, delivery information, and payment methods. For business customers, company names and VAT numbers may also have been affected. However, De Bijenkorf stated that payment card details, bank account numbers, usernames, and passwords were not stored by the logistics provider, suggesting that these sensitive data were likely not compromised.

Customer accounts are also believed to be secure, as no login credentials were involved in the breach. The investigation is ongoing to determine the extent of the data exposure and the number of affected individuals.

Recent Trends in Cyberattacks on Retail

This incident is part of a broader trend where cybercriminals are increasingly targeting retail chains by compromising their suppliers and service providers. Earlier this week, Polish convenience store giant Żabka reported unauthorized access to its internal systems after an external service provider’s account was compromised. Fortunately, customer-facing services and payment systems remained unaffected.

In July, Lidl also disclosed that customer information from its online stores in Germany, Belgium, and the Netherlands was exposed due to a breach involving one of its IT service providers. Such incidents illustrate the vulnerabilities that exist within supply chains and the potential ripple effects on retail operations.

Implications for the Retail Sector

The attack on De Bijenkorf underscores the importance of robust cybersecurity measures for both retailers and their third-party partners. As cybercriminals continue to exploit weaknesses in supply chains, retailers must prioritize securing their external relationships to protect customer data and maintain operational integrity.

As the investigation unfolds, it remains crucial for De Bijenkorf and similar retailers to enhance their cybersecurity protocols and ensure that their logistics partners are equally vigilant against potential threats.

This report is based on information published by therecord.media.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

spot_img

Related articles

Recent articles

Atlassian Rovo Vulnerability Allows Data Exfiltration from Jira and Confluence

Recent findings have revealed a vulnerability in Atlassian's Rovo assistant that allows attacker-controlled instructions to extract data from Jira and Confluence. This issue was...

Qilin Ransomware Claim: Stade Français Investigates Data Leak After Cyberattack

Qilin Ransomware Claim: Stade Français Paris has confirmed it was targeted by a cyberattack that disrupted its information systems. The club reported that it...

Georgia Investigates Alleged Foreign Disinformation Campaign Targeting Russian Tourists

Georgia Investigates Alleged Foreign Disinformation Campaign Targeting Russian Tourists. The State Security Service of Georgia has initiated a criminal investigation into a purported disinformation...

Untrusted Data Safety

Microsoft Defender’s attack disruption now includes device isolation, a new response action that enhances protection for compromised endpoints. This capability was recently highlighted in...