Observed Signal · Aug 5, 2026 · Security Incident · Source: Retail-News · Impact: 2/5 · Sentiment: Negative
Series of Cyberattacks Hits European Retailers
A wave of cyberattacks has affected several European retailers, highlighting growing risks in digitally connected supply chains. Reported incidents include logistics disruptions at Dutch department store De Bijenkorf after an attack on an external logistics partner; a data breach at French group Intermarché affecting about 300,000 Click-&-Collect users (names, emails and contact details exposed; payment data and passwords reportedly not affected); and a compromise at Polish convenience chain Żabka via a third-party service account, giving attackers access to internal systems while store operations and payment systems remained functional. The cases underscore an increase in supply-chain attacks that exploit third-party vendors to bypass core defenses, prompting calls for broader security strategies across retailers and their supplier ecosystems.
Multiple European retailers were hit via attacks on third-party vendors and logistics partners, highlighting an increasing trend of supply-chain compromises that can disrupt operations and customer data — relevant to retail operations, digital commerce and vendor risk management but not an industry-shifting platform policy change.
Track DepositPhotos Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- De Bijenkorf experienced major logistics disruptions after a cyberattack on an external logistics partner, affecting online orders, returns and refunds.
- Intermarché reported a cyberattack exposing around 300,000 Click-&-Collect users' personal data (names, email addresses and contact details); payment data and passwords were reportedly not affected.
- Żabka was attacked via a compromised account of an external service provider, allowing attackers to access internal systems while store operations, payment systems and the customer app remained functional.
- The incidents illustrate a trend of increasing supply-chain attacks targeting retailers through third-party vendors and digital infrastructure.
Connected Companies & Entities
2 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Cyberattack on De Bijenkorf Logistics Partner Disrupts Operations
A cyberattack on an external logistics partner has significantly disrupted operations at Dutch department store chain De Bijenkorf, which is part of the Selfridges Group. Online order fulfillment, returns and refunds have been delayed while stores, the webshop and the mobile app remain operational. Retail Detail reported that unauthorized actors accessed parts of the logistics provider's IT systems; De Bijenkorf has secured affected systems, engaged external cybersecurity and forensic experts, notified affected customers and reported the incident to the data protection authority. It remains unclear whether personal customer data was exfiltrated. The incident highlights growing supply‑chain cybersecurity risks for retailers and the need to include external partners in security strategies and contingency planning.
CEVA Cyberattack Disrupts De Bijenkorf Online Sales
A cyberincident at logistics provider CEVA Logistics is disrupting operations for multiple European retailers. De Bijenkorf says many items are unavailable online and deliveries delayed after a CEVA distribution centre in Tilburg—serving both its stores and e‑commerce—was affected; it has published a customer FAQ. Ace & Tate routed frame orders to in‑store pickup while continuing to ship contact lenses. About You is investigating possible unauthorized access to CEVA systems and has moved affected logistics processes to other sites. Media reports name marketplace Bol among CEVA customers, and some firms (including Valve) have notified customers about potential exposure of personal data. CEVA has indicated that customer names, addresses, phone numbers and order data may have been exposed; passwords and payment details are reportedly not believed to be leaked. Investigations are ongoing.
Ceva Logistics hack exposes customer data across Europe
Ceva Logistics, a France-headquartered global shipping and logistics company, suffered a cyber intrusion that has impacted at least eight European warehouses and resulted in the theft of customer personal information. The attack, which industry reporting says began on July 29, has caused shipping delays and order cancellations for multiple retailers and organizations that use Ceva for fulfillment. Affected parties named in reporting include Dutch retailers Bol and De Bijenkorf, football club Ajax, bank ING, eyeglass maker Ace & Tate, and game company Valve (which notified Steam hardware customers). Ceva confirmed the intrusion on Aug. 1, said it is investigating, restored some services, and is working with authorities; the Dutch data protection authority has received breach reports from 10 organizations.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
