Particle.news
Download on the App Store

Lidl Discloses Third-Party Breach That Stole Customer Contact Data

Exposed names, phone numbers, email addresses and birthdates raise the risk of targeted phishing and identity fraud as investigators probe whether payment or credential data were also taken

Overview

  • Lidl said last week that unknown attackers briefly accessed a separately stored file at an unnamed IT service provider and stole customer data used by its online shop.
  • The company confirmed the stolen fields include salutations, full names, telephone numbers, email addresses, dates of birth and customer numbers.
  • Lidl says the online shop system itself was not affected and the affected service provider has filed a police report while IT forensics teams work to determine the full scope.
  • The firm notified customers in Germany, Belgium and the Netherlands and warned people to expect phishing or identity-fraud attempts using the exposed information.
  • The incident underscores the risks of third-party vendor files for major retailers and leaves open key questions about how many customers were hit and whether passwords or payment details were exposed, which could trigger regulatory follow-up.