The Modern Blindspot: How Two Companies Lost 400,000 Customer Records Without Getting Hacked
Bol and De Bijenkorf just disclosed a massive breach. 400,000+ customers. Names, addresses, phone numbers, order history. Already for sale on the dark web.
Here's the terrifying part: Their systems were never touched.
Clean firewalls. Perfect security posture. Yet customer data walked out the back door.
CEVA Logistics, their third-party logistics vendor, got breached on August 1st. Hackers accessed order-processing systems holding customer data. Bol and De Bijenkorf didn't get hacked. They got exposed through the vendor they trusted.
Hackers Don't Hack Anymore. They Log In Your Vendors.
Why attack Bol's infrastructure when you can walk into CEVA's, grab customer data already sitting there, and leave? Your vendor has the keys. You gave them the keys.
The attacker needed a credential. That's it. No zero-days. No sophisticated techniques. Just access that shouldn't exist or was poorly managed. Now they're inside CEVA's environment, copying records.

Your firewall never sees it. Your SOC sees normal traffic. Your incident response team is asleep. Because the breach isn't happening to you. It's happening to the third party you gave permission to hold your data.
Why This Keeps Happening
Vendors are lower security priority than you. CEVA Logistics is a $18.3B company, but their security posture is different from a major retailer's. Threat actors know this. They attack where defenses are weakest for the same data access.
One vendor breach equals multiple company breaches. CEVA handles dozens of retailers. One compromised credential accesses data from ten companies simultaneously.
Vendors get assessed once at contract time, then trusted forever. No continuous monitoring. No ongoing audits. No behavior baselines. Just faith.
Most critically: You have zero visibility into what your vendors are actually doing with your data right now. You can see everything in your own environment. You can't see anything in theirs.
What Bol and De Bijenkorf Thought vs. Reality
Thought: CEVA is reputable. They passed our security assessment. We trust them.
Reality: They had vulnerabilities. Assessment was years old. Trust isn't a security control.
Thought: If something goes wrong, we'll detect it.
Reality: The breach happened in CEVA's systems. Your SOC was monitoring the wrong place. By detection time, data was already for sale.
This Is Standard Operating Procedure Now.
Amgen. Patient data stolen from third-party vendors. EY. Compromised through a vendor. Deutsche Bank. Went through a vendor. LastPass. Vendor breach. Rockstar Games. Third-party compromise. Polymarket. Malicious code via compromised vendor.
List of all the third party breaches this year
The pattern is identical: Primary company's defenses stay intact. Vendor's don't. Data walks out anyway.
Your firewall can't help because the attack isn't coming through your perimeter. It's coming through the trusted door you built for vendors. By the time you find out, 400,000 records are already for sale.
The Visibility Gap Killing You

Most companies know: The contract. The certifications. The initial assessment from years ago.
Most companies don't know: What systems vendors are actually connected to. What data they're touching. What credentials they're using. Whether those credentials are being abused right now. Whether vendors are already compromised. What normal access looks like versus anomalies.
You've created a massive attack surface you can't see. Hundreds of vendors. Thousands of active connections. Each one a potential entry point.
Vendor risk assessments happen once at contract time. Then the vendor is trusted forever. No audits. No visibility. Just faith they're handling your data responsibly.
How FrontierZero Solves This

We see every external identity accessing your environment. Not abstract vendor risk. Real people. Real credentials. Real sessions.
We track individual credentials, MFA posture, login patterns, devices, browsers, location and much more. You see the identity behind every connection. Is this credential logging in from the vendor's office during business hours? Or a datacenter IP at 3 AM? Does he use a VPN?
We build pattern of life for each external identity. Vendor admin logs in Amsterdam 9-5 CET? That's the baseline. API token fires once per hour? Expected. Service account reads data but never modifies? That's the boundary.
When an identity deviates, you know immediately. Compromised credential logging in from Moscow at 2 AM. API token suddenly making 100x requests. Service account escalating privileges it's never used. Device fingerprint completely different.
Why the vendor uses one app from Amsterdam and 20 minutes later a different one from Eastern Europe without a VPN?
We see deviations before exfiltration happens. You act at the identity level instead of losing 400,000 customer records.
The Questions You Need to Answer Today
• Which external identities have access to your critical data right now?
• What credentials are they using?
• Are they using MFA?
• When should they be logging in versus when are they actually logging in?
• If a vendor credential got compromised, how long before you'd detect unusual behavior? Hours? Days? After the data's already been sold?
If you can't answer these questions, you have the same problem Bol and De Bijenkorf had. They found out when customers started getting phished.
You can't defend what you can't see. Most companies can't see their vendors at all.
Start with visibility. Know what's actually connected to your environment. Know what access your vendors really have. Know what normal looks like so you can spot when something breaks.
Get Your Free External Connections Report
Get our External Connections Report and see every external identity with access to your data. Every vendor credential. Every API token. Every third-party connection.
No guessing. No trust. Just visibility into what's actually touching your systems right now.