Lidl has disclosed a significant data breach that affected customers in Germany, Belgium, and the Netherlands. The incident occurred when hackers breached the systems of an external service provider, allowing them to steal personal information from Lidl’s online shop customers.
The discount supermarket chain has over 376,000 employees and operates 12,000 stores across Europe and the United States. In a notification sent to affected customers via email last week, Lidl revealed that hackers had accessed a file containing customer data, including names, addresses, phone numbers, emails, dates of birth, and customer IDs. However, the company assured its customers that their online shop passwords, payment information, and shipping addresses were not compromised.
Lidl’s IT security standards are reportedly high, but despite these measures, the attackers managed to gain access to a stored file containing sensitive data. The breach was discovered last week, and since then, Lidl has taken steps to notify affected customers and warn them about potential phishing attacks that could use the stolen information.
As part of its response to the incident, Lidl has notified the Dutch Data Protection Authority and advised customers in the affected countries to be cautious when receiving unsolicited emails or messages. The company emphasized that it currently has no concrete evidence of data misuse but is taking precautions to prevent potential identity abuse or phishing attempts.
The hacked service provider has also filed a police report and engaged IT forensic experts to investigate the full scope and impact of the breach. This incident serves as a reminder of the importance of having robust security measures in place, not only for individual companies but also for external service providers that handle sensitive data on their behalf.
In an era where cybersecurity threats are becoming increasingly sophisticated, it’s essential for businesses to test every layer of their defenses before attackers do. Regular breach and attack simulation tests can help identify vulnerabilities and ensure that detection systems like SIEM and EDR rules are working as intended. This proactive approach can prevent many attacks from slipping through the net undetected.
For customers affected by this incident, it’s essential to remain vigilant and cautious when receiving emails or messages that ask for sensitive information or try to elicit a reaction. By staying informed and taking steps to protect their personal data, individuals can minimize the risk of falling victim to phishing attacks or identity theft. As Lidl continues to investigate this incident and take steps to prevent similar breaches in the future, it’s crucial for businesses and customers alike to remain proactive and vigilant in the face of evolving cybersecurity threats.
Source: Bleeping Computer — 2026-07-13