Snapshot from Aug 01, 2026 at 07:00 UTC. For live data and tracking: View Live
Business data breach

Lidl data breach via third-party provider

Analysis based on 6 articles · First reported Jul 13, 2026 · Last updated Jul 15, 2026

Sentiment
-30
Attention
2
Articles
6
Market Impact
General
Live prominence charts, article sentiment distribution, and event development timeline available on the Ergen Dashboard

The breach may erode customer trust and lead to regulatory scrutiny under GDPR, potentially resulting in fines. However, the limited scope of exposed data and swift response may mitigate long-term reputational damage for Lidl.

retail cybersecurity

Lidl, the German discount supermarket chain owned by Schwarz Group, disclosed a data breach affecting online shop customers in Germany, Belgium, and the Netherlands. The breach occurred at a third-party IT service provider, where attackers briefly accessed a file containing personal data including names, phone numbers, email addresses, dates of birth, and customer numbers. Passwords, payment details, and addresses were not compromised. Lidl notified affected customers and relevant data protection authorities, including the Dutch Netherlands — Autoriteit Persoonsgegevens. The service provider filed a police report and engaged forensic experts. While no evidence of data misuse has been found, Lidl warned customers of potential phishing and identity fraud attempts. The incident raises questions about third-party security controls and GDPR compliance.

60 Lidl disclosed data breach
50 Lidl warned of phishing
40 Lidl notified authorities Netherlands — Autoriteit Persoonsgegevens
20 Boris Cipot praised response Lidl
priv
Lidl is the affected retailer; the breach impacts its online shop customers in three countries, prompting customer notifications and regulatory reporting.
Importance 100.0 Sentiment -30.0
priv
Schwarz Group is Lidl's parent company; the incident reflects on its overall data security posture.
Importance 50.0 Sentiment -20.0
cnt
Germany is one of the affected countries; the breach involves German customers.
Importance 30.0 Sentiment 0.0
cnt
Belgium is one of the affected countries; Lidl notified Belgian customers and authorities.
Importance 30.0 Sentiment 0.0
cnt
The Netherlands is one of the affected countries; Lidl notified the Dutch Data Protection Authority.
Importance 30.0 Sentiment 0.0
govactor
The Dutch data protection authority was notified of the breach and may investigate.
Importance 20.0 Sentiment 0.0
subs
Synopsys — Black Duck Software is mentioned as the employer of a security expert who commented on the breach; not directly involved.
Importance 10.0 Sentiment 0.0
per
Boris Cipot, a security engineer, praised Lidl's response and advised customers on precautions.
Importance 10.0 Sentiment 0.0
Schwarz Group related Germany
Germany related Belgium
Germany related Netherlands
Belgium related Netherlands
ERGEN INTELLIGENCE
Track this event live

Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.

Open Dashboard

About Ergen

Ergen is a news intelligence platform that converts raw news articles into structured data. It tracks events, entities, and the relationships between them, with sentiment and attention metrics derived from thousands of articles. Pages on this site are daily static snapshots from the platform's live database. For real-time tracking, search, and alerts, the full dashboard is at app.ergen.ai.