Overview
- Lidl informed affected customers after an IT service provider discovered that unknown actors had accessed and copied a separately stored file containing customer records.
- The stolen fields include salutation, first and last name, phone number, email address, birthdate and customer number, while Lidl says passwords, payment details, postal addresses and customer accounts were not compromised.
- The affected provider has filed a criminal complaint and hired outside forensic investigators to secure systems and analyse the incident while Lidl notified relevant data‑protection authorities and began cross‑border inquiries.
- There are no confirmed signs of misuse so far, but Lidl warns customers to watch for phishing and identity‑theft attempts and to change any passwords they reuse on other sites.
- Cybersecurity experts and coverage point to a wider pattern of supplier‑side breaches that leave firms legally responsible for partner security and could prompt tighter audits, contractual controls and regulatory scrutiny across Germany, the Netherlands and Belgium.