2026 Lidl — webshop third-party provider breach; names, emails, phones, DOBs (Jul)
Data compromised
Per Lidl customer notifications and Heise: salutation, first and last name, telephone number, email address, date of birth, and customer number from webshop accounts. Lidl states passwords, postal/billing/delivery addresses, bank details, and payment data were not affected and customer accounts were not compromised; some notification wording could not rule out broader categories pending investigation
Technical writeup
Verified data protection incident — disclosed July 10, 2026. Lidl, the Schwarz Group discount supermarket chain, emailed affected online-shop customers in Belgium, Germany, and the Netherlands after an IT security incident at a third-party service provider enabled unauthorized access to a customer-data file. Heise and NL Times report exfiltrated fields include name, phone number, email address, date of birth, and customer number; Lidl's spokesperson told Heise postal addresses, passwords, and payment information were not affected and customer accounts were not compromised. Cybernews reviewed customer-notification language stating Lidl could not yet rule out passwords, billing or delivery addresses, bank details, or other payment information, highlighting ongoing forensic uncertainty. Lidl notified data protection authorities in Belgium, Germany, and the Netherlands, filed a police report in Germany, and engaged external security experts; the company said it had no evidence of data misuse at disclosure. Victim count had not been publicly disclosed at catalog time.
Root cause
Unauthorized access to customer data at a third-party IT service provider for Lidl's online shop; not the central shop database per Lidl
References
- https://www.heise.de/en/news/Lidl-shop-data-leak-Customer-data-stolen-from-service-provider-11361418.html
- https://nltimes.nl/2026/07/10/supermarket-chain-lidl-warns-customers-data-leak
- https://cybernews.com/security/lidl-bank-details-risk-security-fail/
- https://www.lalibre.be/economie/entreprises-startup/2026/07/10/fuite-de-donnees-chez-lidl-des-tiers-ont-eu-acces-a-des-donnees-de-clients-26BCNUMN4BG2NIGFYUMRKNIIWU/