Skip to content

Lidl: Customer data from online shop compromised via external service provider

The point: A security incident at an external service provider enabled attackers to access customer data from Lidl’s online shop in multiple EU countries.

Retail customer Lidl has confirmed a security incident at an external service provider in which customer data from its online shop was retrieved. Customers in Belgium, Germany, and the Netherlands are affected.

Lidl has disclosed a data breach: An external IT service provider working for the company became the target of a cyberattack. Unknown attackers thereby obtained customer data from the Lidl online shop. The company notified affected customers in Belgium, Germany, and the Netherlands immediately after discovering the incident.

The incident demonstrates a typical attack surface in the ecosystem of large retail enterprises: External service providers with access to customer data become vulnerabilities when their own security infrastructure is not at the required level. For CISOs, this represents a critical implication for supply chain risk management — not only internal IT security is relevant, but also the security of all third-party providers with data access.

In the context of the NIS2 Directive, such incidents are subject to enhanced reporting obligations. Critical infrastructures and large enterprises must report significant security incidents to authorities and communicate transparently with affected parties. For Lidl and other retail companies, this is not only a compliance matter, but also an opportunity to review third-party risk management and incident response processes.


Source: www.security-insider.de · Published 20 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.

Share on: