

On 1 August, bol was informed of a cyber incident involving one of our warehousing partners. The partner's investigation has shown that unauthorized parties gained access to some of its systems and data. The incident involves two systems used to process orders from one of bol’s distribution centres. No bol systems were affected. However, customer data processed through this location may have been accessed or copied.
Upon discovering the incident, the warehousing partner immediately took measures to stop the unauthorized access and engaged external cybersecurity specialists to conduct a further investigation. As a precaution, bol immediately suspended all data exchanges with this partner. These will only resume once it has been confirmed that this can be done safely.
As personal data of bol customers may have been involved, bol has reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Customers whose data may have been affected will be informed directly.
The incident also impacts part of our logistics operation. Products from bol and selling partners stored at the affected location have been temporarily taken offline, and some orders have been cancelled or may experience delays. All other bol logistics locations remain operational.
We take the protection of personal data and the continuity of our services very seriously. We are working closely with our warehousing partner to minimise the impact on customers, selling partners, and suppliers as much as possible.
Update as of 20/08
Over the past few weeks, bol, CEVA, and external specialists have been working intensively to restore the affected systems and assess the situation following the security incident at CEVA. Based on the available information, the recovery measures taken, and CEVA’s confirmation that the environment can be used safely to resume operations, we have decided to carefully and gradually restart operations at this warehousing facility.
Bol’s systems were not affected by the incident. The protection of customer data remains our highest priority. We continue to closely monitor the situation and remain in close contact with CEVA regarding the ongoing recovery process.
Our goal is to restore the level of service that customers, selling partners, and suppliers expect from us as quickly as possible, without compromising on security or due diligence.
FAQ Securty incident at a warehousing logistics partner
What exactly happened?
On 1 August, a warehousing partner that works with bol informed us of a security incident affecting its systems. Based on the partner’s investigation, unauthorized parties may have gained access to systems and data used to process orders from one of bol’s distribution centres.
The warehousing partner immediately implemented measures to prevent further unauthorized access. In addition, cybersecurity specialists were engaged to investigate the cause and extent of the incident.
No bol systems were affected. At this stage, the incident appears to be limited to two systems operated by this partner.
Is this a data breach?
Because unauthorized parties may have had access to customers’ personal data, we are treating this incident as a data breach. For that reason, we have reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and are directly informing customers whose data may have been involved.
What data may have been accessed?
The data potentially involved consists of information required to process and deliver an order. This may include a customer’s name, address details, email address, phone number, order number, EAN, track & trace information, and order details.
This does not involve all customer data held by bol. Only data stored in the affected systems of the warehousing partner may be impacted.
If your data may have been involved in the incident, you will have received an email from bol informing you about it. At the bottom of the email, you can find the order concerned. This order, along with the associated personal data, was present in the affected systems at the time of the security incident and could therefore have been involved.
You can view this personal data yourself in your bol account. This includes the name and email address you use with bol. In your bol account, under My bol > Orders > Order details, you can see which data is involved: your telephone number (if applicable to this order), order number, EAN, track-and-trace information, and the delivery address associated with that specific order.
What is EAN?
EAN data refers to the information associated with an EAN code (European Article Number). An EAN is a unique identification code for a product, usually the 13-digit number found beneath a barcode on a product's packaging.
Why does bol need this data and why was it shared with the warehousing partner?
bol processes and shares personal data with the warehousing partner to the extent necessary to fulfil the agreement with you, namely to process, ship and deliver your order. bol only shares the personal data that is necessary for this logistics service. Contractual agreements are in place with the logistics warehousing partner regarding the processing and security of personal data.
Were any bank account numbers, payment details, or passwords accessed or compromised?
No, no bank account numbers, payment details, or passwords were accessed. The warehousing partner does not hold this information.
How many customers were affected?
We cannot yet provide final numbers. Customers whose data may have been involved have been informed directly.
Did bol fail to properly oversee its warehousing partner?
We maintain high standards for all parties we work with, including requirements related to information security. Unfortunately, cyberattacks can occur despite extensive security measures.
Our current focus is on minimizing the impact of this incident and carefully investigating its cause and consequences.
Could this have been prevented?
It is too early to determine that. The investigation into the cause of the incident is still ongoing. Once we have more clarity, we will carefully review the findings and take any additional measures that may be necessary.
Why does bol work with a company that became the victim of a cyberattack?
Our warehousing partner is an international logistics service provider that supports logistics operations for many organizations.
Unfortunately, cybercrime remains a risk for organizations worldwide. The fact that a company becomes the victim of a cyberattack does not automatically mean that its security measures were inadequate. This is currently being investigated.
When did bol communicate about this?
We first established the facts and investigated which customers may have been affected. Once sufficient information was available to accurately notify the affected customers, we did so. The affected customers were informed on 5 August. In addition, we notified the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) of the incident on 3 August.
What does this mean for customers?
For some customers, the incident may affect both their order and their personal data.
Orders processed through the affected location may experience delays or have been cancelled. In addition, personal data required for processing and delivering orders may have been viewed or copied by unauthorized parties.
For this reason, we have informed affected customers directly and advise them to remain alert to phishing attempts and other types of fraud. At this time, there is no indication that payment information, passwords, or bol customer login credentials were affected, and there is no evidence to suggest that customers need to take any direct action.
What should customers do if they received this email?
We recommend that customers remain alert to phishing attempts and other forms of fraud. Always check the sender of messages carefully, do not click on links from unexpected emails, and never share personal information if you are asked to do so unexpectedly.
At this time, we have no indication that the potentially affected data has actually been misused, and there are no indications that customers need to take any immediate action.
Why is bol informing customers if it is not certain that their data has been misused?
We believe it is important to be transparent. If there is a possibility that personal data has been viewed or copied, we believe customers should be made aware so that they can take appropriate precautions and remain alert to possible misuse.
Has bol reported the incident to the Dutch Data Protection Authority?
Yes. Because personal data of bol customers may have been involved, bol has reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Is bol’s service still safe?
Yes. Our website, app, and all other logistics locations remain operational. No bol systems were affected by this incident.
We continue to monitor the situation closely and are taking additional precautionary measures where necessary.
Will affected individuals receive further updates?
Should the situation change and warrant further communication with affected individuals, we will, of course, inform them as soon as possible. This FAQ will also be updated on an ongoing basis to reflect the latest developments.
How can I request access to and/or deletion of my personal data?
You can easily manage this yourself through your customer account under “Data & Preferences” > “Exercise Privacy Rights.”
Please also refer to the question: “Which data may have been accessed?”
I have questions about the status of my order and/or pre-order. Can you provide an update on its status, and where can I go if I have any further questions?
If you have questions about the status of your order and/or pre-order, please contact our Customer Service team at 030 - 310 4999 (NL) or +32 (0) 27 885 999 (BE), or send an email to klantenservice@bol.com.
I selected “pay later” as my payment method. Can I still make my payment securely?
Payments are entirely unrelated to the security incident. You can continue to make payments securely and safely.
Are there any ways I can better secure my account?
The security incident that occurred is unrelated to your account and its security. No passwords, bank account numbers, or payment details were accessed. That said, we understand that the security of your account is important to you and that you may want to take additional measures to protect it. One option is to enable two-factor authentication (2FA). This adds a second layer of security in addition to your password, such as a security key on your smartphone, a fingerprint, or facial recognition.
I read that data is being offered on the dark web. Is this correct?
To date, we have found no indications that data is being offered on the dark web. We continue to actively monitor the situation.
Why does the warehousing partner need my phone number and email address?
The email address is used to generate a Track & Trace (shipping) code. The phone number is only shared when a delivery appointment needs to be scheduled.
FAQ Security incident - Update 19/08
Why are some customers only now being notified about the incident?
During the ongoing investigation, additional findings have come to light. These findings showed that more customers may have been affected by the incident than could previously be determined. As soon as we had sufficient certainty about this, we informed those customers directly.
Does this mean the earlier communication was incorrect?
The earlier communication was based on the information that was available and validated at that time. The investigation into the incident is still ongoing. In an investigation of this scale, new insights can emerge over time. We believe it is important to be transparent and to inform affected customers as soon as information has been verified.
Why did it take so long for this to become known?
Determining exactly which data was involved in a security incident is a complex process. It involves examining and validating large volumes of data. While we want to inform customers as quickly as possible, we also want to avoid sharing incomplete or inaccurate information.
Why are some customers receiving another email?
Additional investigation has shown that more orders may have been affected by the incident than was previously known. As a result, these customers are receiving an update with the most current information available.
Why are some customers receiving a notification even though no order is mentioned?
In some cases, personal data was found in the affected systems, but it is not currently possible to link that data to a specific order. As a precaution, we are also informing these customers.
How is it possible that some customers have an affected phone number, while others do not?
The data stored in the affected systems varied by customer and by order. As a result, the types of personal data that may have been involved also vary. A phone number is only involved if a delivery appointment was arranged for an order.
Can bol rule out that more customers may be affected?
The investigation is still ongoing. We believe it is important to be transparent and to inform affected customers as soon as information has been verified. If new relevant findings emerge, we will also inform any additional customers who may be affected.
How many additional customers are being informed?
We do not share numbers. All customers who have been identified as potentially affected are being informed directly.
How far back could my data have been exposed?
The investigation into the security incident is still ongoing. We are currently examining exactly which data was present in the affected systems and the period of time it may relate to. Therefore, we cannot yet definitively determine how far back potentially affected data may date. Despite this uncertainty, we wanted to inform you that your data may have been involved in this incident.
Does this indicate that the investigation was not carried out properly?
No. In fact, a thorough investigation often uncovers new findings over time. With security incidents, it is not unusual for the full scope to become clear only as the investigation progresses. We choose to inform customers as soon as new findings have been sufficiently confirmed.
What is bol doing to protect customers?
We are working closely with CEVA and external specialists to investigate the impact of the incident. In addition, we are informing affected customers directly, providing them with practical information and advice, and continuing to monitor any new developments.
Was bol allowed to store this data with CEVA?
Certain personal data must be shared with logistics partners in order to process and deliver orders. This is subject to contractual agreements and security measures designed to protect personal data. Despite these safeguards, a security incident occurred at CEVA.
How can customers trust that bol has the situation under control if more customer data appears to be involved than initially thought?
In an investigation of this scale, new findings can emerge over time. We believe it is important to be transparent and have deliberately chosen to inform affected customers as soon as new findings have been verified. The investigation is being carried out carefully, and if it shows that additional customers may be affected, we will inform them directly. That is what we are doing now. We believe transparency is more important than waiting until every detail has been conclusively established.

