← Lidl

2026 Lidl — webshop third-party provider breach; names, emails, phones, DOBs (Jul)

2026 Unknown records affected Share on X

Data compromised

Per Lidl customer notifications and Heise: salutation, first and last name, telephone number, email address, date of birth, and customer number from webshop accounts. Lidl states passwords, postal/billing/delivery addresses, bank details, and payment data were not affected and customer accounts were not compromised; some notification wording could not rule out broader categories pending investigation

Technical writeup

Verified data protection incident — disclosed July 10, 2026. Lidl, the Schwarz Group discount supermarket chain, emailed affected online-shop customers in Belgium, Germany, and the Netherlands after an IT security incident at a third-party service provider enabled unauthorized access to a customer-data file. Heise and NL Times report exfiltrated fields include name, phone number, email address, date of birth, and customer number; Lidl's spokesperson told Heise postal addresses, passwords, and payment information were not affected and customer accounts were not compromised. Cybernews reviewed customer-notification language stating Lidl could not yet rule out passwords, billing or delivery addresses, bank details, or other payment information, highlighting ongoing forensic uncertainty. Lidl notified data protection authorities in Belgium, Germany, and the Netherlands, filed a police report in Germany, and engaged external security experts; the company said it had no evidence of data misuse at disclosure. Victim count had not been publicly disclosed at catalog time.

Root cause

Unauthorized access to customer data at a third-party IT service provider for Lidl's online shop; not the central shop database per Lidl

References