If you’ve ordered online from bol, de Bijenkorf, Ace&Tate, and Ajax, or picked up a gift through ING’s Points shop, your name and delivery details may have been caught up in a data breach.
While none of these companies were hacked directly, cybercriminals were able to breach their logistics company, CEVA Logistics, which packed and shipped their online orders.
Here’s what to know about the data breach, and why your deliveries might take longer than usual.
What data has actually been leaked?
If you’re stressing about your banking info finding its way onto the dark web, you can rest easy.
All the affected companies stress that no payment details, IBANs, or credit card numbers were leaked, as the logistics firm only processes the payment method (i.e. whether you’ve paid through iDeal or credit card), not your actual bank details.
Similarly, your account information is safe; no usernames or passwords were involved in the breach.
However, cybercriminals have managed to get their hands on the information found on your shipping label. According to de Bijenkorf and bol, this may include:
- your name and contact details (including your mobile number and email address),
- your address,
- track and trace information,
- company name and VAT information (if you’ve included this in your order),
- your order number,
- and what specifically you’ve ordered.
Let op: If you’re a zzp’er with a very old VAT number (btw nummer), that figure may contain your BSN.
Meanwhile, if you’re an ING customer, the data breach only affects those who’ve ordered physical products via ING Punten (Points).
And were you ever banned from an Ajax stadium? Ajax warns that your name, address, and date of birth may have been accessed. As of August 13, the club has personally informed all individuals whose data has been leaked.
Will my orders be delayed?
Unfortunately, deliveries are the hardest hit.
While de Bijenkorf still allows online ordering, the shop notes that “processing of orders, returns, and refunds may take longer than customers are used to.”
This is echoed by bol, with the Dutch webshop warning that “some orders have been cancelled or may experience delays.”
Similarly, if you bought something via ING points between August 1 and 5, your order has likely been cancelled. According to the bank, your “purchase amount and ING Points will be refunded within 10 working days.”
Planning to reorder? At present, you won’t be able to make any orders with ING’s points, so you’ll have to hang tight for now.
If you’ve placed an online order from Ace&Tate, you’ll likely only be able to pick it up at a physical store — at the moment, the only home deliveries being made are for contact lenses.
What should you do?
In general, you’ll only hear from the companies if your data has actually been caught up in the breach. However, as investigations are currently still ongoing, your data may still have been leaked — even if you don’t receive any email.
The real danger, however, is in phishing attempts.
Ajax warns customers to “be extra vigilant about suspicious emails and never to simply click on links or open attachments from unknown senders.”
De Bijenkorf also stresses that you “never share your password, payment details, or personal information via email or phone.” None of these companies will request that information from you via email or phone.
Want to make sure DutchReview pops up on your news feed more often? Just add us as a preferred news provider, and we’ll handle the rest.





