Lidl data breach via third-party provider
Analysis based on 6 articles · First reported Jul 13, 2026 · Last updated Jul 15, 2026
The breach may erode customer trust and lead to regulatory scrutiny under GDPR, potentially resulting in fines. However, the limited scope of exposed data and swift response may mitigate long-term reputational damage for Lidl.
Lidl, the German discount supermarket chain owned by Schwarz Group, disclosed a data breach affecting online shop customers in Germany, Belgium, and the Netherlands. The breach occurred at a third-party IT service provider, where attackers briefly accessed a file containing personal data including names, phone numbers, email addresses, dates of birth, and customer numbers. Passwords, payment details, and addresses were not compromised. Lidl notified affected customers and relevant data protection authorities, including the Dutch Netherlands — Autoriteit Persoonsgegevens. The service provider filed a police report and engaged forensic experts. While no evidence of data misuse has been found, Lidl warned customers of potential phishing and identity fraud attempts. The incident raises questions about third-party security controls and GDPR compliance.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard