Particle.news
Download on the App Store

Lidl Says Third‑Party Hack Exposed Contact and Identity Data of Online Shop Customers

Investigations are under way with customers warned to expect targeted phishing and identity‑fraud attempts.

Overview

  • Lidl disclosed that an external IT service provider was breached last week and attackers stole customer contact and identity fields including full names, phone numbers, email addresses, dates of birth and customer numbers.
  • The supermarket chain said its online shop systems were not compromised and that passwords, billing and delivery addresses and payment details are not believed to be affected.
  • The affected notifications were sent to customers in Germany, Belgium and the Netherlands and Lidl has reported the incident to police and national data protection authorities.
  • The hacked service provider and Lidl have restored security and engaged independent IT forensic experts to determine the full scope, while no threat actor has been publicly identified.
  • Customers were told to be vigilant for convincing, targeted phishing and impersonation scams that can use names, emails, phone numbers and birth dates to appear legitimate.