← All articles

redaction

WEBA (BE) hit by Qilin: ransomware, customer data accessed, 48 h recovery

On August 10, 2026, Belgian retailer WEBA was hit by a ransomware attack. Customer data was accessed; operations resumed on August 12. Qilin claimed responsibility on August 16; WEBA says no ransom was paid.

On August 10, 2026, Belgian furniture retailer WEBA detected an intrusion followed by ransomware deployment. Store and e‑commerce operations were disrupted, but a controlled recovery took place by August 12. WEBA states no ransom was paid and customer passwords/account access were not compromised. On August 16, the Qilin group claimed responsibility.

Key facts

Operating in Ghent, Deinze, Tongeren and Mons, WEBA reports that potentially accessed data includes identity, contact details (phone, email, address), and order/purchase information. Operations were restored in about 48 hours thanks to planned recovery and strong backups.

Legal framework

  • GDPR — notification duties: GDPR Articles 33 and 34 require notifying the competent authority and, where there is a high risk, communicating with affected individuals.
  • NIS 2: retail is not systematically covered, but critical providers may be. See the NIS 2 directive for obligations and notification timelines applicable to in-scope entities.
  • CTI practice: claims on leak sites (Qilin, Aug 16) are not legal proof; victim confirmation (here, WEBA via RetailDetail) substantiates the operational reality of the incident.

What this means for Luxembourg businesses

  • Cross‑border risk: seemingly “basic” data enables targeted phishing and fraud (fake support/delivery), particularly with BE–LU customer flows.
  • Business continuity: WEBA’s case underlines the need for a tested business continuity and disaster recovery plan with immutable backups and controlled restart scenarios.
  • Notification governance: trigger early risk analysis to calibrate GDPR notifications and monitor any suppliers that might fall under NIS 2.

Immediate actions this week

  • Validate ransomware resilience: measure actual RTO/RPO, test 3‑2‑1‑1‑0 restores, segment networks, and document controlled restart procedures.
  • Prepare GDPR notifications: Article 33/34 templates, day‑0 to day‑3 decision flow, anti‑phishing guidance, and dedicated support channels.
  • Secure e‑commerce/logistics chain: review access and logs (hoster, ERP, PSP, WMS/TMS), deploy phishing‑resistant MFA, harden integrations (API, SFTP), and enable dark‑web monitoring to detect potential data releases.

Sources

RetailDetail (FR/NL) for WEBA’s public confirmation; CTI trackers for Qilin’s August 16 claim.

Article generated by Luxgap regulatory watch. For tailored guidance on this topic, contact us.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →