Lidl disclosed a customer data breach affecting users of its online shop in Germany, Belgium, and the Netherlands after attackers compromised an external IT service provider and briefly accessed a separately stored file. The retailer said its online shop systems were not breached directly, but the exposed data includes customer names, telephone numbers, email addresses, dates of birth, salutations, and customer numbers.
Lidl said it cannot yet rule out exposure of passwords, billing and delivery addresses, bank details, or other payment information, although it has not reported concrete evidence of misuse so far. The service provider has restored system security, filed a police report, and engaged forensic experts, while Lidl notified the relevant data protection authority, including the Dutch regulator, and warned affected customers to watch for phishing attempts and identity fraud.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Lidl disclosed the customer data breach, warned affected customers about phishing and identity fraud risks, and said it had notified the relevant data protection authority, identified in one report as the Dutch Data Protection Authority.
Following the breach, the affected IT service provider reportedly restored system security, filed a police report, and engaged IT forensic experts to investigate the incident.
Lidl said unidentified attackers briefly accessed a separately stored file at one of its external IT service providers, exposing customer data tied to online shop users in Germany, Belgium, and the Netherlands. Lidl stated its online shop systems themselves were not affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceitpro.com
Open sourceitsecurityguru.org
Open sourceteiss.co.uk
Open sourcebleepingcomputer.com
Open sourceservice.lidl.nl
Open sourcehelpnetsecurity.com
Open sourcecustomerservice.lidl.be
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.