Skip to content
Back to Blog
7 min readdata-breachretailphishingsupply-chain

Lidl data breach: webshop customer data stolen through an IT service provider

Lidl began emailing webshop customers on 10 July 2026 to tell them their data had been stolen, not from Lidl's own systems, but from a file held by one of its IT service providers. Names, dates of birth, phone numbers and customer numbers are gone. Passwords and payment data are not. The number of affected customers was not disclosed.

TL;DR

On 10 July 2026, Lidl confirmed a data breach originating at one of its IT service providers, where unknown parties briefly accessed a separately stored file and stole part of the webshop customer data in it. Exposed fields include full names, dates of birth, phone numbers, email addresses and customer numbers. Passwords, addresses and payment data were not taken. Lidl did not disclose the provider's identity or the number of affected customers, and warned customers to expect phishing.

Incident Response PlaybookExpand
  1. Confirm with the supplier exactly which of your data sets were in the exposed file, and over what window.
  2. Get the supplier's written incident report: what was accessed, what was copied, which controls failed.
  3. Determine your role under the AVG. If the data is yours and the supplier is your processor, the notification duty is yours.
  4. Establish when your own 72-hour clock starts: the moment you became aware, not the moment the supplier discovered it.
  5. Preserve the supplier's forensic findings and evidence before retention windows close.
  6. Establish the exact fields exposed per individual. Name plus date of birth plus customer number is a phishing kit, treat it as one.
  7. Assess whether notification to the Autoriteit Persoonsgegevens is required, and file within 72 hours of becoming aware if it is.
  8. Notify affected customers or employees with specific guidance on what the data enables (targeted phishing) and what it does not (account takeover, since no passwords).
  9. Warn people about the exact lure: personalised messages using their real name and customer number. Tell them what a genuine message from you looks like.
  10. Brief your own service desk to expect impersonation attempts and inbound questions from worried customers.
  11. Review every other supplier that holds copies of the same data. One exposed export rarely means only one exists.
  12. Run a phishing simulation calibrated to the lures this specific data enables, and measure the click rate before and after.

When the leak lives at a supplier your customers never chose

On 10 July 2026, Lidl began emailing webshop customers to tell them their personal data had been stolen. The Lidl data breach did not happen inside Lidl's own webshop. It happened at one of the company's IT service providers, in a separately stored file that unknown parties reached and copied from. Names, dates of birth, phone numbers, email addresses, and customer numbers are gone. Passwords and payment data are not. That specific combination is worth pausing on, because it is close to the ideal starting kit for a phishing campaign.

What happened

Lidl's account, sent directly to affected customers and confirmed in coverage by Security.nl and VRT NWS, is vague on some points and precise on others. Unknown parties briefly gained access to a file held by an external IT service provider, and stole part of the customer data in it. The webshop platform itself was not breached, and Lidl says customer accounts were not compromised.

According to Security.nl, Lidl told customers to verify the sender of any unexpected message and avoid clicking unknown links. The company apologised for the inconvenience in its emails. The IT service provider engaged forensic investigators and filed a police report, and the Autoriteit Persoonsgegevens, the Dutch data protection authority, was notified.

Two things Lidl did not disclose: the identity of the IT service provider, and the number of affected customers. Reports also differ on geographic scope. Security.nl lists the Netherlands, Belgium, and Germany. VRT NWS, reporting the Belgian side, describes it as the Belgian webshop. The safe reading is that customers in at least the Netherlands and Belgium are affected, and possibly Germany.

How the attack worked

Here is the honest position: the attack method is not public, and neither is the identity of the supplier that held the file. Lidl describes brief unauthorised access to a separately stored file. That phrasing points to a dataset sitting outside the main webshop application, perhaps an export, a backup, or a working copy used for some operational purpose. That is an inference on our part, not a confirmed fact, and we will flag it as such.

What is worth stating plainly is the shape of the failure. The data that ends up stolen in incidents like this is often not in the hardened production system. It is in the copy. A file exported for analysis, migration, or support, then stored somewhere with weaker controls than the system it came from, is a recurring theme in supplier breaches. No group has claimed responsibility, and Lidl reports no concrete evidence of misuse so far. This early, absence of evidence means very little.

Who is affected

Webshop customers who created an account, in at least the Netherlands and Belgium. Lidl has not published a number, and declined to give one when asked. The exposed fields are full name, date of birth, phone number, email address, and customer number.

Notice what that list is missing and what it contains. No password, so there is no direct account-takeover path from this data alone. No bank or payment details, so there is no direct route to financial theft. What remains is a clean identity record: a real name tied to a real date of birth, a real phone number, and a customer number that proves the person actually shopped at Lidl. For a phishing operator, that is worth more than a password. A password gets patched by a reset. A name, a date of birth, and proof of a real customer relationship do not expire, and they make the next fake email far more convincing.

What this means for your organisation

Lidl is a consumer breach, and most of the coverage frames it that way. For a Dutch or Belgian organisation, there are two lessons here that have nothing to do with groceries.

The data you hand to a supplier is still your breach. Lidl did not lose this data from its own webshop. A provider did, from a file the provider was holding. Under the AVG, that distinction does not move the responsibility away from Lidl. If you push personal data to a processor, a payroll bureau, a CRM host, a mail platform, an analytics vendor, their incident becomes your notification duty and your reputation problem. The controller stays on the hook to inform the individuals and the regulator. The practical control is unglamorous: know which suppliers hold copies of your data, know how those copies are secured, and know how fast the supplier will tell you when something goes wrong.

The phishing that follows this breach will not look like phishing. Think about what an attacker can now write. An email addressed to the customer by full name, quoting their real Lidl customer number, wishing them well around their actual date of birth, and asking them to confirm something to keep their account active. No typos. No strange sender that a five-minute training video would catch. This data is the raw material for exactly the lures that get past trained-but-tired employees and customers. The same pattern lands on your organisation the moment your people, or your customers, appear in a breach like this.

That is the gap phishing simulation is meant to close. The phishing that follows a breach like the Lidl one arrives with real names and real customer numbers attached, which is precisely what generic awareness training does not prepare people for. SecDesk runs phishing simulations and awareness campaigns built on the lures your people will actually see, not on obvious bait. You can see how that works at secdesk.com/phishing-campaign.

Talk to a senior responder about Lidl data breach: webshop customer data stolen through an IT service provider.

Schedule a response call
Incident response

Need incident response?

088 SECDESK (7323375)

Call us. A senior responder picks up.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now