Lidl has issued a warning to some of its European customers to be wary of phishing messages after it revealed personal information may have been compromised in a cyber incident affecting a third-party IT firm.
The incident impacted customers in Germany, Belgium, and the Netherlands, the supermarket owned by Schwarz Group, a German retail company, said.
“Despite high IT security standards, unidentified individuals were briefly able to access a separately stored file containing customer data and steal some of it. The online shop system itself was not affected,” Lidl said in a note to customers.
The firm said it became aware of the incident last week. Stolen data includes full names, email addresses, phone numbers, customer numbers, and dates of birth. Customers of the supermarket’s online store were affected in the breach.
“At this time, we can rule out the possibility that passwords, billing and delivery addresses, bank details, or other payment information are affected,” Lidl assured.
“Your customer account has not been compromised. Although we currently have no concrete evidence of data misuse, we are warning you, as a precaution, against possible phishing or identity theft attempts.”
Lidl credited its third party IT provider, saying it “reacted immediately” in restoring disrupted systems. Relevant authorities have been contacted, and forensics experts have been consulted to investigate the incident.
Recommended reading
- OpenAI Dumps API Analytics Provider Following Data Breach
- No User Data Impacted in Third-party Breach, OpenAI Says
- Rockstar Games Suffers Hack in Third-party Cloud Breach
Following the incident, Lidl has warned impacted customers that their compromised data may be leveraged in phishing attempts.
The supermarket giant is urging customers to verify the authenticity of email and SMS senders, and to not disclose any personal data or click on external links if they notice anything unusual





