Particle.news
Download on the App Store

Lidl Customer Records Copied in Third‑Party IT Provider Breach

Copied customer records have prompted a criminal complaint, external forensic probes, notification of data‑protection authorities.

Overview

  • Lidl informed affected customers after an IT service provider discovered that unknown actors had accessed and copied a separately stored file containing customer records.
  • The stolen fields include salutation, first and last name, phone number, email address, birthdate and customer number, while Lidl says passwords, payment details, postal addresses and customer accounts were not compromised.
  • The affected provider has filed a criminal complaint and hired outside forensic investigators to secure systems and analyse the incident while Lidl notified relevant data‑protection authorities and began cross‑border inquiries.
  • There are no confirmed signs of misuse so far, but Lidl warns customers to watch for phishing and identity‑theft attempts and to change any passwords they reuse on other sites.
  • Cybersecurity experts and coverage point to a wider pattern of supplier‑side breaches that leave firms legally responsible for partner security and could prompt tighter audits, contractual controls and regulatory scrutiny across Germany, the Netherlands and Belgium.