Lidl discloses online shop breach after service provider hack

Lidl Discloses Online Shop Breach After Service Provider Hack, Warns Customers of Potential Phishing Attacks

German discount supermarket chain Lidl has notified customers in Germany, Belgium, and the Netherlands that their personal information was stolen in a breach at a service provider. The company’s online shop was not directly affected by the attack, but customer data stored separately was accessed and partially stolen.

The incident occurred when attackers breached a third-party IT service provider that supports Lidl’s operations. The compromised data includes customers’ names, addresses, phone numbers, email addresses, dates of birth, and customer account numbers. Fortunately, Lidl has assured its customers that passwords, payment information, and shipping addresses were not accessed.

Lidl, which operates 12,000 stores across Europe and the United States, notified affected customers via email last week and published separate notifications on its support websites in Belgium and the Netherlands. The company also informed the Dutch Data Protection Authority of the data breach and warned customers to be vigilant against potential phishing attacks that might use the stolen information.

In a statement, Lidl emphasized that it maintains high IT security standards and has taken measures to prevent similar incidents in the future. The company is working with IT forensic experts to investigate the full scope and impact of the incident, and has filed a police report to assist with the investigation.

The fact that this breach occurred at a third-party service provider highlights the importance of robust security measures within an organization’s supply chain. Companies often rely on external providers for various services, including IT support, which can create vulnerabilities if not properly secured.

While Lidl’s notification and response to the incident are commendable, it serves as a reminder that even with robust security measures in place, data breaches can still occur. Organizations must remain vigilant and proactive in monitoring their systems and networks to prevent such incidents.

In light of this breach, customers should be cautious when receiving unsolicited emails or messages that request sensitive information or prompt them to click on suspicious links. Phishing attacks often use stolen data to trick victims into divulging more personal information or installing malware. By being aware of these tactics, individuals can better protect themselves from potential identity theft and other cyber threats.

As a practical takeaway for readers, it’s essential to regularly review and update your online accounts’ security settings, including passwords and two-factor authentication. This will help prevent unauthorized access to sensitive information, even if you’re affected by a data breach like the one experienced by Lidl customers.


Source: Bleeping Computer — 2026-07-13