Supplier cyberattack disrupts De Bijenkorf customers

Supplier cyberattack disrupts De Bijenkorf customers

De Bijenkorf’s supplier cyberattack disrupted orders, returns, refunds, and trust. The incident demonstrates how third-party systems can turn a technical breach into an immediate customer-experience and operational problem.


A cyberattack affecting a logistics provider used by De Bijenkorf has delayed orders, returns, and refunds, showing how a third-party technology failure can spread rapidly into customer service and retail operations.

The Dutch department store group’s shops, website, and application remained available, but parts of its fulfilment process were disrupted because systems operated by the external provider could not function normally.

De Bijenkorf is also investigating whether personal information was accessed during the incident. The available information has not established the full extent of any data exposure, and the disruption remains under examination.

Although the visible sales channels continued to operate, the infrastructure required to complete transactions had been compromised. Customers may be able to browse products and place orders, but their experience still depends on warehouse management, stock records, carrier integration, returns processing, payment reconciliation, and refund systems.

When one of those components becomes unavailable, the retailer remains the organisation customers hold responsible. Most shoppers do not distinguish between a brand’s own systems and those operated by a logistics, payments, software, or customer service contractor.

Supplier resilience is therefore closely tied to customer experience. Delayed deliveries and refunds can damage trust quickly, particularly where customers have paid premium prices or need clarity about the status of personal information.

The incident follows a series of attacks in which retailers, manufacturers, and consumer goods companies have experienced operational disruption through suppliers and contractors. Attackers can exploit smaller organisations with weaker controls as an indirect route into larger commercial ecosystems.

The growing cyber responsibilities facing company boards already extend beyond an organisation’s immediate network. De Bijenkorf’s disruption shows why supplier dependencies need to be included in governance, continuity planning, and investment decisions.

Conventional procurement checks often establish whether a supplier holds a security certification, maintains insurance, or has documented controls. Those questions do not necessarily reveal how quickly the supplier can detect an attack, isolate affected systems, restore service, or communicate dependable information to commercial partners.

Retailers need a detailed understanding of which services are operationally critical and what happens if each one becomes unavailable. A logistics company may appear to be a single supplier, but its service can depend on several software platforms, cloud providers, subcontractors, and carrier connections.

That complexity can obscure responsibility during an incident. Contracts may define liability and notification requirements, yet legal provisions do not restore orders or process refunds. Operational teams need tested alternatives, manual procedures, and clear authority to prioritise customers when normal systems fail.

Data mapping is equally important. When a retailer does not know precisely which customer information a supplier stores, where it is held, and how long it is retained, assessing a potential breach becomes slower and less reliable.

Delayed certainty can increase regulatory exposure and weaken customer communications. The wording and timing of those communications often determine whether an operational problem develops into a broader reputational crisis.

Customers generally accept that incidents can occur, but they expect prompt acknowledgement, realistic timeframes, and clear guidance about payments, refunds, deliveries, and personal information. Vague assurances tend to create further frustration when service remains disrupted.

Retailers may also need to consider the financial resilience of critical suppliers. A severe cyber incident can produce recovery costs, lost income, legal claims, and contractual penalties that threaten a smaller provider’s viability.

Heavy dependence on a supplier without understanding its ability to withstand a crisis creates a second continuity risk. Even after systems have been restored, the commercial relationship may remain vulnerable if the provider cannot absorb the financial consequences of the incident.

As retail systems become more interconnected, resilience depends less on defending a single corporate perimeter. Order management, warehousing, payments, marketing, customer support, and delivery increasingly operate through a network of external services.

Specialist providers can offer scale, technology, and flexibility that would be expensive for a retailer to build internally, but operational control is shared across organisations with different systems, incentives, and levels of security maturity.

De Bijenkorf’s experience shows that a retailer can keep its storefront open while losing important parts of the service customers believe they are buying. Supplier cyber risk belongs within decisions about fulfilment, brand reputation, customer retention, and board-level resilience rather than remaining confined to technical due diligence.



  • European M&A deals of the month: July 2026

    European M&A deals of the month: July 2026

    July’s European deal market rewarded scale, infrastructure, and operational depth. Five major transactions showed buyers paying substantial premiums for established networks, recurring revenue, specialist technology, and market positions that would take years to recreate.


  • Financial stress consumes workers’ annual leave

    Financial stress consumes workers’ annual leave

    Financial stress is consuming annual leave intended for worker recovery. Research among 2,002 UK adults found employees were also skipping food, working while ill, avoiding workplace events, and delaying holidays because of cost.


  • Electric vans reach record UK market share

    Electric vans reach record UK market share

    Electric van registrations reached record market share during July’s recovery. Battery-electric vehicles captured 14.7% of the monthly market, although year-to-date adoption remains below half the mandated level.