Overview
- Lidl said last week that unknown attackers briefly accessed a separately stored file at an unnamed IT service provider and stole customer data used by its online shop.
- The company confirmed the stolen fields include salutations, full names, telephone numbers, email addresses, dates of birth and customer numbers.
- Lidl says the online shop system itself was not affected and the affected service provider has filed a police report while IT forensics teams work to determine the full scope.
- The firm notified customers in Germany, Belgium and the Netherlands and warned people to expect phishing or identity-fraud attempts using the exposed information.
- The incident underscores the risks of third-party vendor files for major retailers and leaves open key questions about how many customers were hit and whether passwords or payment details were exposed, which could trigger regulatory follow-up.