386/69 Wednesday, July 15, 2026

Lidl, a German discount supermarket chain under the Schwarz Group, has notified online shop customers in Germany, Belgium, and the Netherlands after attackers stole personal data in a data breach affecting an external IT service provider. Lidl is part of the Schwarz Group, Europe’s largest food retailer, with more than 376,000 employees and approximately 12,000 stores across Europe and the United States. The company notified affected customers by email last week and published separate notices on its customer support websites in Belgium and the Netherlands.
According to Lidl’s notice, although the service provider maintains a high standard of IT security, threat actors were able to briefly access separately stored files containing customer data and steal some of the information. The stolen data belongs to online shop customers and includes titles, first names, last names, phone numbers, email addresses, dates of birth, and customer numbers. However, Lidl confirmed that the online shop system itself was not affected and that the attackers did not directly access the online shop.
Lidl stated that passwords, payment data, billing addresses, shipping addresses, bank details, and other payment information were not affected, and customer accounts were not compromised. The company has reported the incident to the Dutch Data Protection Authority and warned affected customers to remain alert for phishing attempts or impersonation scams that may use the stolen information. At this time, there is no clear evidence that the data has been misused. In addition, the affected IT service provider has filed a police report and engaged IT forensics specialists to thoroughly investigate the incident and its impact.
