Lidl confirms data breach affecting European customer data
Passwords and bank details are safe.

People entering supermarket chain Lidl store. Mike Kemp/In Pictures via Getty Images.
- Lidl notified customers in Belgium, Germany, and the Netherlands after a third-party service provider suffered a data breach.
- Stolen data includes names, phone numbers, emails, birth dates, and customer numbers from Lidl’s online shop.
- Lidl says passwords, addresses, bank details, payment data, and customer accounts were not affected.
- Authorities were notified, police reports filed, and customers warned to watch for phishing or identity misuse.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Discount supermarket Lidl has notified customers of a data breach involving their personal information. Affected customers are asked to be vigilant for phishing attempts.
Affected shoppers in Belgium, Germany, and the Netherlands have received an email informing them of what happened.
The email says that one of Lidl’s third-party service providers experienced an “IT security incident” that enabled an unknown attacker to access detailed customer information from Lidl’s online shop.
The exfiltrated data includes first and last names, telephone numbers, email addresses, dates of birth, and customer numbers.
For the moment, we can exclude that passwords, billing and delivery addresses, bank details or other payment information are affected. Your customer account has not been compromised,a machine translation of Lidl statement reads.
The discount supermarket assures customers that the affected service provider responded immediately and took the necessary steps to fully restore the affected IT systems. In addition, Lidl filed a police report and hired external security experts to launch an investigation into the incident.
The data protection authorities in Belgium, Germany, and the Netherlands have been notified of the incident.
Although there’s no evidence that the stolen data has been misused, the discounter recommends being alert for possible phishing attempts.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
“Be vigilant for unexpected messages. Always verify the authenticity of the sender. If you notice anything unusual, don’t provide any data and don’t click on unknown links,” the discounter warns.
Lidl says it was notified of the incident at the beginning of last week, but chose to go public on Friday, July 10th. The number of customers affected by the data breach is unclear. As of writing, no hacking group has claimed responsibility.
The article was updated with a statement from Lidl. We are quoting it in full. The article has also been amended to reflect the company’s official position that passwords, billing and shipping addresses, bank details or other payment information belonging to their customers were not affected.
“We were informed of an IT security incident at one of our IT service providers. Our IT service provider responded immediately and took the necessary measures to restore full security to the affected IT systems.
Unknown persons were briefly able to access a separately stored file containing customer data and steal parts of it despite high IT security standards. The stolen data includes customer information of our online store customers (title, first and last name, phone number, email address, date of birth, customer number).
We have currently no concrete evidence of data misuse. Nevertheless, as a precaution, we warned affected customers against possible phishing attempts or identity abuse.”