On Wednesday, 5 August 2026, Bol confirmed that cybercriminals may have viewed or copied customer personal data and order details at logistics partner CEVA Logistics. Payment data and passwords do not appear to be affected, but the mix of names, addresses and precise product info can enable highly convincing fraud in the age of generative AI.
The cyberattack hit two CEVA Logistics systems used for orders from one Bol distribution center. Bol’s website, app and internal systems were not hacked, according to the company.
CEVA informed Bol on 1 August, and Bol reported the incident to the Dutch Data Protection Authority on 3 August. As a precaution, the company has suspended data exchanges with the logistics partner. The number of potentially affected customers and the attack method are not yet known.
What data may have been exposed?
Attackers may have accessed data needed to process and deliver orders. According to Bol, this could include:
- name, address, postal code and city;
- phone number and email address;
- order number and track-and-trace details;
- ordered items and associated EAN codes;
- a personal message attached to a gift card.
An EAN code is the unique barcode number that identifies a specific product. It does not grant account access, but it can reveal which item someone purchased.
Bol states that only data from CEVA’s affected system could be involved. This does not concern customers’ full order histories. Recipients of a warning email can check at the bottom of the message which order or items may be involved.
There are currently no indications that passwords, login credentials, bank account numbers, credit card details or other payment information were accessed. The ongoing investigation will determine whether additional data was impacted.
Why does AI make this breach riskier?
Generative AI makes it easier to turn stolen data into credible phishing at scale. Criminals no longer need to handcraft hundreds of emails. A language model can automatically produce unique messages for each affected customer based on their order details.
For example, an attacker could generate a message using the customer’s real name, the correct product and a valid order number—then claim the package can’t be delivered until a small fee is paid.
Such a message might look like this:
“Your order for [product] with order number [number] could not be delivered. Please verify your address and pay €1.95 in new delivery costs.”
Most parts of that message can be factually correct. Only the payment link and the request are fake.
AI can also tailor language to a target’s likely age, region or communication style. Models can write flawless Dutch, mimic existing customer service messages and push the same campaign across email, SMS, WhatsApp and social media.
AI also scales up phone scams
The risk isn’t limited to written phishing. Criminals can combine leaked data with AI voice generation and automated calling systems.
A scam caller may pose as an employee of Bol, CEVA or a courier and reference a real order. They might claim a refund is pending, the delivery address needs confirmation, or a canceled order must be repaid.
Modern AI voices make it possible to run these calls automatically and at scale. Systems can respond in real time and pivot when a person hesitates.
That shifts the impact of a seemingly limited breach. The criminals may not have passwords or payment data, but they do have enough context to build trust—the first step toward extracting sensitive information.
Accurate personal details prove nothing
A message that includes your real name, order or track-and-trace code isn’t automatically legitimate. Criminals use leaked data precisely to make fakes look authentic.
Always verify outside the message you received. Open your order directly in the official Bol app, or type bol.com yourself into your browser. Avoid links in unexpected emails, texts or chat messages.
Bol advises affected customers to stay alert to phishing and other fraud. The company says it currently has no evidence that the potentially accessed data is being misused.
What should affected customers do now?
You don’t need to block your bank card solely because of this incident. A password change is also not immediately necessary if your Bol password has not been reused or shared elsewhere.
A few precautions are smart:
- check at the bottom of the warning email which order may be affected;
- access orders only via the official app or website;
- never pay unexpected delivery, admin, or return fees via a link you received;
- never share passwords, payment details, or SMS codes by phone, email, or chat;
- keep a close eye on valuable or not-yet-delivered orders;
- save bol’s alert in case abuse is detected later.
If you logged in via a suspicious message, change the used password immediately. If you transferred money or entered payment details, contact your bank right away.
Suppliers are becoming prime targets
The incident shows that securing a major digital platform doesn’t stop at its own site and servers. Online retailers share data with warehouses, carriers, payment providers, software vendors, and customer service partners.
Attackers can therefore strike an external partner with access to valuable operational data. This is a supply chain attack: criminals reach the end target via an organization in its ecosystem.
CEVA and bol extended their partnership in June 2025 through at least 2029. CEVA processes platform orders from multiple warehouses.
The attack does not automatically mean CEVA lacked proper
security measures. The cause is still under investigation. The incident does underscore that companies should scrutinize what personal data partners receive, how long it’s stored, and whether all that information is truly necessary.
Limited data leak, lingering fraud risk
For now, the immediate damage appears limited since payment data and account passwords were not affected. The real danger starts when criminals use the leaked details as building blocks for personalized manipulation.
Generative AI makes that process faster, cheaper, and more convincing. A single stolen database can spawn thousands of unique messages, phone calls, and fake pages that mirror real orders.
Affected customers should expect package scams, bogus refunds, and calls about delivery issues in the coming weeks and months. The core rule is simple: verify every request through your official account, and never trust a sender solely because they know your correct personal details.