Bol. ING. Ajax. Ace & Tate. De Bijenkorf. Five powerhouse brands. Five devastating data leaks. One frustrating reality: not a single one of them suffered a direct breach. The attack hit a shared delivery partner. But when customer data gets leaked, nobody remembers the vendor, they remember your brand. Your perimeter doesn't stop at your firewall. It extends to every software vendor, delivery partner, and third-party contractor you use. One vendor slip-up can torch years of customer trust in seconds.
Four breaches, one shape
In February, Odido told 6.2 million customers that their names, addresses, phone numbers, bank account details, dates of birth, and passport numbers were exposed. Nobody wrote a line of exploit code to get in. Someone simply called customer service, posed as an internal IT employee, and talked their way into access. A standard phishing campaign did the rest.
In April, ransomware took down the patient records software at ChipSoft. ChipSoft runs the systems behind roughly three out of four Dutch hospitals. Eleven of those hospitals, including Erasmus MC, disconnected on the spot to protect themselves. Whether patient data actually left the building is still under investigation, and ChipSoft has not said how the attackers got in.
In August, the target was CEVA Logistics. They are the fulfillment company that packs and ships orders for a long list of Dutch retailers. CEVA was compromised on August 1. By August 5, customers of Bol, De Bijenkorf, Ajax, ING, and Ace & Tate were reading breach notifications. Their names, addresses, phone numbers, and order details may have been viewed or copied. On August 9, the picture got worse. CEVA’s own employee records, including temporary staff, turned out to be exposed too. It is the second publicly known incident at CEVA in nine months. A group calling itself Coinbase Cartel claimed to be selling a full copy of their database back in November 2025.
Five days later, on August 11, Simian reported its own breach. Simian is the Groningen company behind Reclameland, Drukland, and Flyerzone, representing about 500,000 customers combined. Attackers grabbed email addresses and hashed passwords. A small number of customers had actual credit card details intercepted. This was serious enough that Simian called those people directly rather than trusting an email to reach them.
Five companies, five sectors, one clear pattern: attackers found the one weak door in a system, the external services providers that countless other companies quietly depend on, and everyone downstream inherited the bill.
The Technical Root Cause
Behind these major third-party breaches lies the exact same operational failure. Hackers rarely write sophisticated exploits. Instead, they exploit untrained employees with basic phishing, target default configurations on servers and work stations, abuse poorly maintained antivirus setups, and exploit vulnerable, unpatched web applications to gain entry. The companies in the headlines didn’t get hacked directly: their back-office vendors did.
The Real Danger: Puzzle Piece Data
Dismissing a breach because "it was only address data" is a dangerous mistake. Cybercriminals operate by aggregating stolen datasets. A name from one leak, a phone number from another, and an order history from a third are stitched together to build targeted, highly convincing phishing scams against your users. When attackers combine this with common password reuse, a single vendor breach becomes an entry point into personal accounts, banking apps, and corporate networks.
How spriteCloud Secures Your Extended Perimeter
All of these breaches in a single year is a clear pattern, not a coincidence. It forces an urgent question: what will the next twelve months look like now that the Cyberbeveiligingswet is in force?
We asked Gerard, head of penetration testing at spriteCloud, where third-party security is heading under strict enforcement. His warning is straightforward: If your logistics, payments, or fulfillment stack relies on external partners you have never actively tested against, it is time to close that gap and prevent your company from being the next target.
In 95 percent of our testing engagements, our team gains full administrative access. That is the exact foothold attackers use to pivot sideways through a network and reach partner data. Every tester on our team holds expert practical, hands-on certifications like OSCP, OSWE, or OSEP, earned by breaching live systems rather than studying theory.
NIS2: What "managed" actually has to mean
With new cyber regulations (Article 21(2)(f)) now in force, self-reported vendor questionnaires are no longer enough. Paper policies cannot prove whether a network is secure. True risk management requires testing the interfaces you actually control:
- API & Data Flows: Audit how customer information is handed off to third parties.
- Access Rights: Limit and monitor the access internal systems grant to external vendors.
- Response Plans: Test incident response against a vendor breach, not just a direct attack.
If your fulfillment, payments or logistics stack depends on a partner you've never actually tested against, get in touch: info@spritecloud.com.
