The European discount grocer says intruders lifted a stored file of online shop customer records, though it maintains passwords and payment details were not exposed.

Lidl, the discount supermarket chain owned by Schwarz Group, has notified online shop customers in Germany, Belgium and the Netherlands that their personal information was stolen in a breach traced to one of its information technology service providers.
The retailer said it learned of the incident last week and reached affected customers by email, while also posting separate notices on its support websites in Belgium and the Netherlands. Schwarz Group ranks as Europe’s largest food retailer, employing more than 376,000 people across roughly 12,000 stores in Europe and the United States.
Lidl said the intrusion did not touch the online shop’s core systems but instead reached a separately stored file holding customer records. "Despite high IT security standards, unknown individuals briefly gained access to a separately stored file containing customer data, and part of the data was stolen from it. The online shop’s system itself was not affected," the company said.
The exposed information includes customers’ salutation, first and last name, phone number, email address, date of birth and customer number, according to the company’s statement.
A Lidl spokesperson told BleepingComputer that passwords, billing and shipping addresses, bank details and other payment information tied to customers were not compromised, and that customer accounts themselves remained secure. "It’s important to note: The online shop’s system itself was not affected. Passwords, billing and shipping addresses, bank details, or other payment information belonging to our customers are explicitly not affected. Customer accounts were not compromised," the spokesperson said.
The company said it has no current evidence that the stolen data has been misused, but is warning affected customers as a precaution to watch for phishing attempts or identity fraud that could exploit the exposed information. Lidl also notified the Dutch Data Protection Authority of the breach.
The IT service provider at the center of the incident has filed a police report and brought in outside digital forensics specialists to determine the full scope and impact of the breach, restoring the security of its systems in the process. No individual or group has been identified as responsible for the attack, and no additional details about the perpetrators have been disclosed.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543