

On 1 August, bol was informed of a cyber incident involving one of our warehousing partners. The partner's investigation has shown that unauthorized parties gained access to some of its systems and data. The incident involves two systems used to process orders from one of bol’s distribution centres. No bol systems were affected. However, customer data processed through this location may have been accessed or copied.
Upon discovering the incident, the warehousing partner immediately took measures to stop the unauthorized access and engaged external cybersecurity specialists to conduct a further investigation. As a precaution, bol immediately suspended all data exchanges with this partner. These will only resume once it has been confirmed that this can be done safely.
As personal data of bol customers may have been involved, bol has reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Customers whose data may have been affected will be informed directly.
The incident also impacts part of our logistics operation. Products from bol and selling partners stored at the affected location have been temporarily taken offline, and some orders have been cancelled or may experience delays. All other bol logistics locations remain operational.
We take the protection of personal data and the continuity of our services very seriously. We are working closely with our warehousing partner to minimise the impact on customers, selling partners, and suppliers as much as possible.
FAQ Securty incident at a warehousing logistics partner
On 1 August, a warehousing partner that works with bol informed us of a security incident affecting its systems. Based on the partner’s investigation, unauthorized parties may have gained access to systems and data used to process orders from one of bol’s distribution centres.
The warehousing partner immediately implemented measures to prevent further unauthorized access. In addition, cybersecurity specialists were engaged to investigate the cause and extent of the incident.
No bol systems were affected. At this stage, the incident appears to be limited to two systems operated by this partner.
Because unauthorized parties may have had access to customers’ personal data, we are treating this incident as a data breach. For that reason, we have reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and are directly informing customers whose data may have been involved.
The data potentially involved consists of information required to process and deliver an order. This may include a customer’s name, address details, email address, phone number, order number, EAN, track & trace information, and order details.
This does not involve all customer data held by bol. Only data stored in the affected systems of the warehousing partner may be impacted.
No, no bank account numbers, payment details, or passwords were accessed. The warehousing partner does not hold this information.
We cannot yet provide final numbers. Customers whose data may have been involved have been informed directly.
We maintain high standards for all parties we work with, including requirements related to information security. Unfortunately, cyberattacks can occur despite extensive security measures.
Our current focus is on minimizing the impact of this incident and carefully investigating its cause and consequences.
It is too early to determine that. The investigation into the cause of the incident is still ongoing. Once we have more clarity, we will carefully review the findings and take any additional measures that may be necessary.
Our warehousing partner is an international logistics service provider that supports logistics operations for many organizations.
Unfortunately, cybercrime remains a risk for organizations worldwide. The fact that a company becomes the victim of a cyberattack does not automatically mean that its security measures were inadequate. This is currently being investigated.
We first established the facts and investigated which customers may have been affected. Once sufficient information was available to accurately notify the affected customers, we did so. The affected customers were informed on 5 August. In addition, we notified the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) of the incident on 3 August.
For some customers, the incident may affect both their order and their personal data.
Orders processed through the affected location may experience delays or have been cancelled. In addition, personal data required for processing and delivering orders may have been viewed or copied by unauthorized parties.
For this reason, we have informed affected customers directly and advise them to remain alert to phishing attempts and other types of fraud. At this time, there is no indication that payment information, passwords, or bol customer login credentials were affected, and there is no evidence to suggest that customers need to take any direct action.
We recommend that customers remain alert to phishing attempts and other forms of fraud. Always check the sender of messages carefully, do not click on links from unexpected emails, and never share personal information if you are asked to do so unexpectedly.
At this time, we have no indication that the potentially affected data has actually been misused.
We believe it is important to be transparent. If there is a possibility that personal data has been viewed or copied, we believe customers should be made aware so that they can take appropriate precautions and remain alert to possible misuse.
Yes. Because personal data of bol customers may have been involved, bol has reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Yes. Our website, app, and all other logistics locations remain operational. No bol systems were affected by this incident.
We continue to monitor the situation closely and are taking additional precautionary measures where necessary.
Should the situation change and warrant further communication with affected individuals, we will, of course, inform them as soon as possible. This FAQ will also be updated on an ongoing basis to reflect the latest developments.
You can easily manage this yourself through your customer account under “Data & Preferences” > “Exercise Privacy Rights.”
If you have questions about the status of your order and/or pre-order, please contact our Customer Service team at 030 - 310 4999 (NL) or +32 (0) 27 885 999 (BE), or send an email to klantenservice@bol.com.
Payments are entirely unrelated to the security incident. You can continue to make payments securely and safely.
The security incident that occurred is unrelated to your account and its security. No passwords, bank account numbers, or payment details were accessed. That said, we understand that the security of your account is important to you and that you may want to take additional measures to protect it. One option is to enable two-factor authentication (2FA). This adds a second layer of security in addition to your password, such as a security key on your smartphone, a fingerprint, or facial recognition.
We are aware of RTL’s reporting and are carefully investigating the situation. At this stage, we are establishing the facts. As soon as more information becomes available, we will add any relevant updates to our information page. If information becomes available that is relevant to individual customers, they will be informed directly.
The email address is used to generate a Track & Trace (shipping) code. The phone number is only shared when a delivery appointment needs to be scheduled.

