Visualização de leitura

Amsterdam’s De Bijenkorf Hit by Logistics Cyberattack, Orders Delayed

De Bijenkorf cyberattack

A De Bijenkorf cyberattack involving one of the retailer's external logistics partners has disrupted order processing, returns, and refunds while raising concerns over potential customer data exposure. The Dutch luxury department store chain said the security incident occurred within the systems of a third-party logistics provider, adding that there is currently no evidence that its own infrastructure was compromised.

The Amsterdam-based retailer confirmed that customers can continue placing online orders and stores remain open. However, deliveries, returns, and refunds are expected to take longer than usual as the investigation continues.

De Bijenkorf Confirms Third-Party Security Incident

According to De Bijenkorf, unauthorized individuals gained access to part of its logistics partner's systems. The logistics provider responded by immediately blocking the unauthorized access and implementing additional security measures.

An external investigation is now underway to determine the cause of the incident, its scope, and whether customer information was affected.

As a precaution, De Bijenkorf has informed customers about the incident and submitted a report to the Dutch Data Protection Authority while awaiting the investigation's findings.

What Customer Data Could Be Affected in De Bijenkorf Cyberattack?

The retailer said investigators are still determining whether any personal information has been compromised.

Based on the information currently available, data that may be involved includes:

  • Customer names and contact details, including email addresses, postal addresses, and phone numbers.
  • Information related to online purchases, such as ordered products, pricing, discounts, delivery details, and the payment method used.
  • For business customers, company names and VAT numbers stored in My Account may also be involved.

De Bijenkorf emphasized that sensitive financial information is not part of the incident. The company said payment details, bank account numbers, credit card information, usernames, and passwords were not accessed.

Investigation Continues as Customers Await Confirmation

The retailer said it is still investigating whether individual customers have been affected. Customers whose information is confirmed to be involved will receive direct communication via email from info@debijenkorf.nl.

For those who have not yet received a notification, the company said it cannot currently rule out the possibility that their information was included in the incident until the investigation is completed.

De Bijenkorf also stressed that no login credentials were compromised, meaning unauthorized individuals cannot access customer accounts using stolen usernames or passwords.

Retailer Warns Customers About Phishing Risk

Although the investigation remains ongoing, De Bijenkorf warned customers to stay alert for a possible phishing risk if personal information is ultimately found to have been exposed.

The retailer advised customers not to click on suspicious links or open unexpected attachments. It also reminded customers never to share passwords, payment information, or personal details through email or phone calls.

The company said it will never request credit card details, gift card information, or other sensitive information via email.

Logistics Cyberattacks Continue to Disrupt Supply Chains

The incident adds to a growing list of attacks targeting organizations that support retail operations rather than retailers directly. A logistics cyberattack can interrupt deliveries, returns, and customer service even when the affected retailer's own systems remain operational.

In July 2026, a ransomware attack on Japan's largest refrigerated logistics company disrupted food deliveries across the country, causing supply shortages for restaurant chains, including Kentucky Fried Chicken. The incident demonstrated how cyberattacks on logistics providers can quickly impact downstream retail operations and customer services.

For now, De Bijenkorf said its stores remain open, online ordering continues to operate, and there are no indications that its own systems have been compromised. The retailer said it will provide additional updates as the external investigation establishes whether customer data was affected and the full extent of the incident.

Angelina Jolie, Robert De Niro Among Hollywood Stars Hit by Tribeca Data Leak

Tribeca Film Festival Data Breach

A Tribeca Film Festival data breach has reportedly exposed the contact information of Hollywood stars including Angelina Jolie, Robert De Niro and Martin Scorsese, alongside details linked to other prominent actors and filmmakers. Cybersecurity researcher Jeremiah Fowler reportedly identified nearly 666,000 records across four databases connected to the annual New York film festival, raising concerns over the exposure of personal and professional information. According to reports, the exposed records included names, phone numbers and email addresses. While several high-profile celebrities were reportedly listed in the databases, sources cited in the reports said most of the leaked contact information belonged to managers and agents representing celebrities rather than the stars themselves.

Tribeca Film Festival Data Breach Exposes 666,000 Records

The alleged data breach was first flagged by Fowler after he discovered four databases containing nearly 666,000 records dating from 2019 through 2026. The information was reportedly connected to the Tribeca Film Festival, which was founded in New York by Robert De Niro and others. Fowler reportedly alerted the festival about the exposure shortly before its 12-day event began on June 3. The exposed information allegedly included contact details that could potentially be used by attackers for targeted phishing or malware campaigns. The researcher also reportedly found a folder containing device information associated with email addresses. The data allegedly indicated details such as the version of an iPhone being used, whether Safari was the browser in use and the software version installed on the device. According to Fowler, such information could provide attackers with additional details that may help them target individuals.

Angelina Jolie, Robert De Niro Among Names Reportedly Exposed

The alleged exposure reportedly involved contact information associated with several well-known Hollywood figures. The names mentioned in reports include Angelina Jolie, Robert De Niro, Martin Scorsese, George Lucas and Danny Boyle. Actors reportedly appearing in the records include Morgan Freeman, Jennifer Lawrence, Winona Ryder, Neil Patrick Harris, Rami Malek, Sharon Stone and Michael Douglas. However, the extent to which the celebrities' own private contact details were exposed remains unclear. A source cited in the reports said the majority of the information reportedly belonged to managers and agents who represent the celebrities. This distinction suggests the databases may have been used for professional communication and coordination connected to the film festival rather than containing direct personal accounts belonging to the celebrities.

Tribeca Film Festival Investigates Alleged Data Exposure

The Tribeca Film Festival reportedly responded after receiving the disclosure from Fowler, saying it takes data security seriously and was actively investigating the matter. The databases have since reportedly been removed from public access. However, it remains unclear how long the information was accessible online or whether unauthorized individuals accessed, copied or misused the exposed data before it was taken down. Jeremiah Fowler, the cybersecurity researcher who identified the exposed databases, told The Cyber Express that he found no evidence of malicious activity. “No, I didn't see any evidence like a ransomware message or something like that,” Fowler said. He added that the database contained “lots of non-sensitive documents like press releases and event details.” According to Fowler, “even if someone found it, they would probably see these type of documents and just ignore it.” However, he said the discovery of a backup file changed the situation. “When I discovered that the database contained a backup file, that's when things got serious,” Fowler said, adding, “It was likely human error why there was a backup file stored in this database.” The reports also clarified that there is no suggestion that the Tribeca Film Festival was directly responsible for the alleged exposure. The organisation has not reportedly provided further public details about the incident beyond its initial response.

Celebrity Data Breach Raises Security Concerns

The alleged celebrity data breach highlights the security risks surrounding databases containing information about public figures and the professionals who work with them. Even when exposed records primarily belong to managers and agents, such information can potentially reveal connections between celebrities and their representatives. The reported inclusion of device information could also provide additional context about the technology used by individuals associated with the records. The incident adds to concerns over how personal and professional data connected to major cultural events is stored, managed and secured online. With the investigation reportedly ongoing, questions remain about the source of the exposure, the duration of public access and whether any of the information was misused.

Bitcoin Depot Discloses $3.6 Million Crypto Theft Following System Breach

Bitcoin Depot cyberattack

The Bitcoin Depot cyberattack has resulted in the theft of approximately 50.903 Bitcoin, valued at $3.665 million, after unauthorized actors gained access to the company’s internal systems. The incident, disclosed in a filing with the U.S. Securities and Exchange Commission (SEC), occurred on March 23, 2026, and involved compromised credentials linked to the company’s digital asset settlement accounts. Bitcoin Depot Inc. confirmed that the attackers were able to access certain parts of its information technology environment and execute unauthorized transfers from company-controlled cryptocurrency wallets.

How the Bitcoin Depot Cyberattack Unfolded

According to the company’s Form 8-K filing, the Bitcoin Depot cyberattack began when an unauthorized party infiltrated its IT systems and obtained control of credentials associated with digital asset settlement accounts. These credentials were then used to transfer Bitcoin without authorization. Upon detecting the breach, the company said it immediately activated its incident response protocols. External cybersecurity experts were brought in to investigate the intrusion, and law enforcement authorities were notified. The company noted that, based on the investigation so far, the incident appears to be limited to its corporate systems and did not impact customer-facing platforms or services.

Financial Impact of the Bitcoin Depot Cyberattack

The unauthorized transfer involved 50.903 Bitcoin, which Bitcoin Depot valued at approximately $3.665 million at the time of the incident. This figure has been recorded as a preliminary estimate of loss in the company’s filing. While the Bitcoin Depot cyberattack has been classified as a material incident due to potential reputational, legal, and regulatory consequences, the company stated that it does not expect the breach to have a significant impact on its overall financial condition or operational performance. However, the final financial impact may change as the investigation progresses. The company also indicated that it maintains cybersecurity insurance, which may cover part of the losses, although there is no guarantee of full recovery.

No Evidence of Customer Data Exposure

Bitcoin Depot emphasized that there is currently no evidence suggesting that customer data was accessed or exfiltrated during the Bitcoin Depot cyberattack. The company stated that its customer platforms, systems, and environments remain unaffected. This distinction is significant, as the breach appears to have been confined to internal systems rather than broader infrastructure that handles customer transactions or personal data. Still, the company acknowledged that the investigation is ongoing and that conclusions could evolve as more information becomes available.

Ongoing Investigation and Security Measures

The Bitcoin Depot cyberattack remains under active investigation, with third-party cybersecurity specialists continuing to analyze the scope and method of the intrusion. The company has committed to updating its disclosures if new material information emerges. As part of its response, Bitcoin Depot is working to strengthen its IT systems and implement additional safeguards aimed at preventing similar incidents in the future. These efforts include reviewing access controls and reinforcing security around credential management. The company also indicated that it will amend its SEC filing if required details were not fully available at the time of the initial report.

Broader Implications for Crypto Security

The Bitcoin Depot cyberattack highlights a key risk in the cryptocurrency sector, compromised credentials tied to internal systems can lead to direct financial losses, even when customer platforms remain unaffected. The incident resulted in a loss of $3.665 million after attackers gained control of settlement account credentials and moved funds from company-controlled wallets. While there is no evidence of customer data exposure so far, the breach reflects the ongoing challenges organizations face in securing digital asset infrastructure. The investigation is still ongoing, and the full scope and long-term impact have yet to be determined. The Cyber Express team has reached out to Bitcoin Depot for additional details; however, no response had been received at the time of writing. We will update this story as more information becomes available.
❌