Lidl says hackers stole customer data from a third-party service provider affecting online shop users in Germany, Belgium and the Netherlands

Lidl says hackers stole customer data from an external IT service provider used for its online shop operations in Germany, Belgium and the Netherlands. The retailer says its shopping platform itself was not breached, but attackers briefly accessed and exfiltrated part of a separately stored customer database. Exposed data includes names, phone numbers, email addresses, dates of birth, titles, and customer numbers; Lidl says passwords, payment data, and addresses were not affected.
Why it matters: Affected customers face a higher risk of targeted phishing and impersonation scams even if payment details were not exposed. Lidl users in the affected countries should be wary of unsolicited messages, verify any account-related communication, and monitor for identity misuse.

Sources

Hackers steal Lidl customer data from external service provider
2026.07.13 100% relevant
This article is the first report here establishing a distinct breach event involving Lidl customer data exposed through a third-party provider.
← Back to all stories