AdobeStock/Syda Productions

Cyberattack at Bol warehouse partner triggers delays and cancellations

You can read this article in 8 minutes

A cyber incident at a warehouse partner working with online retailer Bol may have exposed customer data and disrupted fulfilment operations. Attackers accessed two order-processing systems used at one of Bol’s distribution sites, prompting the retailer to suspend data exchange with the partner. The impact extended beyond IT: parts of the assortment were temporarily removed from sale, some orders were cancelled, and some deliveries are running late.

The text you are reading has been translated using an automatic tool, which may lead to certain inaccuracies. Thank you for your understanding.

Key facts:

  • Unauthorised parties gained access to two order-processing systems operated by a logistics partner serving Bol.
  • Customer data linked to orders handled at the affected site may have been viewed or copied.
  • The information potentially involved includes names, delivery addresses, email addresses, phone numbers, order numbers and parcel tracking details.
  • So far, there is no indication that payment data or passwords were compromised.
  • Bol has suspended data exchange with the partner and temporarily removed part of the assortment.
  • Some orders were cancelled and some shipments are delayed.
  • The incident has been reported to the Dutch data protection authority.
  • Bol’s other logistics locations continue to operate as normal.

The case illustrates how a breach at a supplier can quickly affect a retailer’s day-to-day operations. Even when a company’s own systems are not compromised, disruption at a warehouse, in order-management tools or in data connections can still interrupt sales, dispatch and delivery.

Two order-processing systems compromised at one site

Bol said it was alerted to the incident on 1 August. Based on the logistics partner’s investigation, unauthorised individuals gained access to the partner’s systems and data.

The breach involved two systems used to process orders at one of Bol’s distribution centres.

Bol stressed that its own IT infrastructure was not compromised. However, it cannot rule out that customer data linked to orders routed through the affected location may have been accessed or copied.

Media reports indicate the exposed information could include names, delivery addresses, email addresses, phone numbers, order references and shipment tracking details. At this stage, there is no indication that payment details or passwords were affected.

Data exchange suspended while investigation continues

After detecting the intrusion, the logistics partner blocked unauthorised access and brought in an external cybersecurity specialist to carry out further investigation.

Bol responded by suspending data exchange with the partner. The connection will only be restored once the retailer is satisfied that cooperation can continue securely.

Because personal data may have been involved, the incident was reported to the Dutch data protection authority. Customers whose information may have been affected were contacted directly.

Operational impact: range temporarily reduced, delays and cancellations

The incident also affected day-to-day logistics. Products stored at the affected location — including items from Bol and its retail partners — were temporarily taken offline.

As a result, some orders were cancelled and some deliveries are delayed. Bol said its other logistics centres are operating without disruption.

Bol has not named the partner involved. Media reports have pointed to CEVA Logistics, but the operator has not issued a detailed statement on the matter.

The same cyberattack reportedly also affected Dutch department store chain De Bijenkorf.

When a supplier is vulnerable, the customer is exposed

The incident highlights how dependent e-commerce has become on the digital resilience of logistics providers.

Warehouse and transport systems do more than manage goods flows. They also contain customer records, order details, delivery addresses and tracking data used to monitor shipments end-to-end. When criminals gain access to these environments, the risk is twofold: data exposure and real-world disruption to the movement of goods.

Thorsten Neumann, a NATO civilian expert on cyber threats and a TAPA EMEA expert, previously noted in an interview with Trans.info that breaking into a TMS can even enable a vehicle to be redirected into the hands of thieves. Criminal groups also use artificial intelligence tools to create convincing documents, impersonate business partners and take over transport orders.

How carriers can reduce the risk

Modern software can improve efficiency, but it does not automatically make a business secure. As highlighted by Trans.info, resilience depends on building multiple layers of protection.

Don’t rely on the system alone

TMS platforms, GPS, telematics and automation streamline work — but they do not remove risk. Any system can be attacked, and processes can be bypassed without additional checks.

Carriers should regularly review what protections their TMS provides, who can access sensitive data, and whether employee and subcontractor permissions remain justified.

Confirm changes outside the system

Fraudulent instructions can appear legitimate, particularly if criminals have taken over an email account or gained access to a platform.

Any change to a delivery address, vehicle registration, driver, bank account or collection point should be confirmed via a second channel — for example, a phone call to a previously verified number.

Extra caution is needed when email domains differ only slightly. Switching a suffix from “.de” to “.com” can be enough to convincingly impersonate a partner.

Train teams using real scenarios

Dispatchers, forwarders and drivers need to understand current criminal tactics. A generic warning about phishing is rarely sufficient.

Training is more effective when it draws on real examples: fake transport orders, altered delivery addresses, forged documents and attempts to hijack cargo. Staff should know when to stop execution and who to alert if something looks wrong.

Limit access to shipment tracking data

Location and tracking information is useful for customers and planners, but sharing it too widely increases exposure.

Only people who genuinely need tracking data should have access. Links and location details should not be forwarded without control — especially for loads at higher risk of theft.

Vet subcontractors and platforms

Risk does not stop at a company’s own infrastructure. Weak security at a warehouse operator, freight platform or subcontractor can spread across the supply chain.

It is worth checking what security procedures partners use, how they respond to incidents, and whether they routinely verify accounts, documents and user access.

Have a plan for sudden system shutdowns

The Bol case shows that after a cyber incident, a company may need to cut off data exchange immediately.

Carriers should decide in advance how to operate if they lose access to their TMS, telematics, email or a customer’s system. That plan should include alternative ways to reach drivers, manual order confirmation, document safeguards and clear rules for pausing transports.

Technology can’t replace procedures

Organised criminal groups use many of the same tools that legitimate businesses rely on. They break into systems, produce convincing documents and exploit the time pressure under which dispatch teams and warehouses operate.

That is why effective protection means combining technology with procedures, training and continuous access control. Expensive software without alert staff and clear response rules can create a false sense of security.

The incident involving Bol’s partner also underlines that cybersecurity is not only an IT issue. In logistics, it can directly determine whether an order is fulfilled, whether a load reaches the correct destination, and whether a company retains customer trust.

As recent events have shown, disruptions rarely remain local: they can cascade through supply chains and affect availability, lead times and service levels far beyond the initial incident.

For operators managing complex fulfilment environments, the same resilience mindset applies across warehouse operations, systems and processes.

Tags:

Also read