July 10, 2026: Discount supermarket giant Lidl began emailing online-shop customers across Belgium, Germany, and the Netherlands after an IT security incident at a third-party service provider exposed personal data. The breach is company-confirmed—not a forum rumor—and it hits one of Europe's largest grocery brands at the exact moment shoppers expect parcel-tracking texts and refund links to look legitimate.
What Lidl confirmed
Per Heise and NL Times, unknown attackers accessed a customer-data file maintained by a third-party provider for Lidl's webshop—not Lidl's central shop database. Exfiltrated fields include:
- Salutation, first and last name
- Telephone number and email address
- Date of birth
- Customer number
Lidl's spokesperson told Heise that postal addresses, passwords, and payment information were not affected and that customer accounts were not compromised. NL Times, citing ANP reporting, echoed that billing addresses, delivery addresses, bank details, and payment data stayed out of scope.
Cybernews noted that some customer-notification wording said Lidl could not yet rule out passwords, billing or delivery addresses, bank details, or other payment information—standard cautious phrasing while forensics continue. Treat confirmed fields as exposed; treat the broader categories as under investigation until your personal notice letter says otherwise.
Where customers were notified
Affected shoppers received emails through country-specific Lidl service portals in Belgium, Germany, and the Netherlands. Belgian coverage from La Libre and Dutch outlets including NU.nl amplified the same timeline: Lidl learned of the incident at the beginning of the week and went public Friday, July 10.
Lidl notified data protection authorities in all three countries and filed a police report in Germany. External security experts are investigating. At disclosure, Lidl said it had no evidence the stolen data had been misused—which is not the same as "nothing will happen next week."
Why a grocery webshop leak still matters
No payment cards in the initial confirmed field list sounds like good news. It is—and it is not a free pass. A row pairing your real name, mobile number, email, and date of birth with a Lidl customer ID is enough to craft convincing phishing:
- Fake delivery delays citing your name and a plausible order window
- Refund scams asking you to "confirm" bank details to process a webshop credit
- Account-reset links that harvest passwords on a lookalike Lidl login page
Lidl operates at supermarket scale across Europe. Even a subset of webshop users across three countries can mean a large absolute number of inboxes—Lidl has not published a victim count at the time of this write-up.
What was not exposed (per Lidl)
Based on company statements reported by Heise and NL Times:
- Passwords — stored separately; not in the exfiltrated file per Lidl
- Payment and bank data — not affected per company spokesperson
- Billing and delivery addresses — not in scope per initial confirmation
- In-store loyalty-only shoppers who never used the webshop are unlikely to be in this dataset
If you only buy in physical Lidl stores and never created a webshop account, this incident probably does not involve your row—but rotate reused passwords anyway if you share credentials anywhere.
What to do if you got the Lidl email
- Read your notification carefully for which fields apply to you; country templates may differ slightly.
- Do not click links in unexpected SMS or email about Lidl orders, refunds, or "account verification"—open lidl.com or your national Lidl app directly.
- Enable MFA on the email account tied to your Lidl webshop registration if the provider supports it.
- Change your Lidl password if you reused it on other sites—defense in depth even though Lidl says passwords were not stolen.
- Skeptical of calls citing your DOB or customer number; hang up and call Lidl customer service via the official website number.
Third-party risk, again
The attack vector here is familiar: a vendor file, not Lidl's core ERP. Retailers outsource webshop hosting, CRM exports, and marketing databases constantly. One misconfigured backup or stolen admin credential at a service provider becomes a multinational notification exercise—exactly what played out across Belgian, German, and Dutch DPAs in the same week.
Lidl sits inside the Schwarz Group alongside Schwarz Digits cloud infrastructure. The parent has invested heavily in European tech sovereignty narratives; this incident is a reminder that brand security and supplier security are different ledgers.