Skip to content

Lidl Customer Data Compromised at IT Service Provider

The point: Customer data (name, date of birth, email, phone number, customer number) was leaked from an IT service provider for Lidl; payment data and passwords remained untouched.

An external IT service provider working for Lidl became the target of an attack. Attackers copied customer data from a separate file without compromising the Lidl shop system itself.

Unknown attackers gained access to a customer file stored at a service provider for the Lidl online shop. According to Lidl’s statement, they copied parts of it: salutation, name, date of birth, email address, phone number, and customer number. Payment data, passwords, and the Lidl Plus app were not affected as far as currently known. The online shop system itself remained uncompromised. Lidl informed affected parties in stages; the company did not disclose a final victim count.

For CISOs, this incident is a lesson in third-party risks: while the data is insufficient for direct payment fraud, it is ideally suited for social engineering attacks. With complete names, dates of birth, and phone numbers, attackers can craft highly credible phishing emails. Lidl itself explicitly warns its customers of this danger and recommends they critically review emails claiming to be from the company and, if necessary, access the platform directly using the known URL rather than following links in emails.

According to Lidl, the source lay in the IT infrastructure of the contracted service provider, not in its own network. Lidl has engaged external forensics staff, filed a criminal complaint, and involved the data protection authority. Despite the geographic separation, the online retailer itself is responsible for notification and bears liability—regardless of where the technical error occurred.

Such incidents are a recurring issue in retail. The outsourcing of shipping, data processing, and customer communication to specialized providers multiplies the places where sensitive customer data is stored. The challenge for companies is to enforce uniform security standards across all parties contractually and technically—access rights, logging, and data processing must be controllable at service providers just as they are in their own infrastructure.


Source: www.it-daily.net · Published 13 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: