news.mlab.sh
Back to the feed
data-breach

Hackers steal Lidl customer data from external service provider

Medium
Summary

Lidl, a major European supermarket chain, suffered a data breach after attackers gained access to customer data stored by an external IT service provider. The stolen information included personal details like names, email addresses, and phone numbers, but payment information was not compromised. Lidl is urging customers to be vigilant against phishing scams due to the exposed data.

Lidl, a leading European discount supermarket chain, has disclosed a data breach affecting online shop customers in Germany, Belgium, and the Netherlands. The incident stemmed from unauthorized access to a customer database maintained by an external IT service provider, rather than Lidl’s own online shopping platform. According to notifications sent to affected customers on Friday, attackers briefly accessed the database and exfiltrated a portion of the stored data. The stolen information included customers’ titles, first and last names, phone numbers, email addresses, dates of birth, and customer numbers. Lidl stated that no passwords, billing addresses, or bank details were compromised, and customer accounts remain secure. The company reported being informed of the incident earlier in the week and that the service provider immediately took steps to secure the affected systems. Lidl has also filed a criminal complaint and notified the relevant data protection authority. While Lidl has not identified the specific IT service provider involved, nor attributed the breach to a particular threat actor, it is advising customers to remain cautious and watch out for potential phishing scams and identity theft attempts, given the exposed data could be used in targeted scams. Lidl is part of Germany’s Schwarz Group, operating approximately 12,900 stores across 32 countries and employing around 395,000 people.

Read the full article at The Record