---
title: "Lidl Warns Customers After Third-Party IT Provi… | Firevault"
description: "Lidl has warned online shoppers in Germany, Belgium and the Netherlands that names, phone numbers, email addresses and dates of birth were stolen from a…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/lidl-third-party-it-provider-data-breach#webpage",
      "url": "https://fire-vault.com/news/lidl-third-party-it-provider-data-breach",
      "name": "Lidl Warns Customers After Third-Party IT Provi…",
      "description": "Lidl has warned online shoppers in Germany, Belgium and the Netherlands that names, phone numbers, email addresses and dates of birth were stolen from a…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/7e282b00-eb5e-43e3-affb-4432248059cf/lidl-third-party-breach-20260714-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/lidl-third-party-it-provider-data-breach#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/lidl-third-party-it-provider-data-breach#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Lidl Warns Customers After Third-Party IT Provider Breach",
          "item": "https://fire-vault.com/news/lidl-third-party-it-provider-data-breach"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Lidl Warns Customers After Third-Party IT Provider Breach",
      "description": "Lidl has warned online shoppers in Germany, Belgium and the Netherlands that names, phone numbers, email addresses and dates of birth were stolen from a third-party IT provider. The breach is a fresh reminder that supplier risk is customer risk.",
      "url": "https://fire-vault.com/news/lidl-third-party-it-provider-data-breach",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/7e282b00-eb5e-43e3-affb-4432248059cf/lidl-third-party-breach-20260714-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/7e282b00-eb5e-43e3-affb-4432248059cf/lidl-third-party-breach-20260714-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/7e282b00-eb5e-43e3-affb-4432248059cf/lidl-third-party-breach-20260714-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/7e282b00-eb5e-43e3-affb-4432248059cf/lidl-third-party-breach-20260714-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-07-14T21:50:59.092547+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/lidl-third-party-it-provider-data-breach"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 648,
      "keywords": "Lidl, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Lidl has told customers across Germany, Belgium and the Netherlands to be on guard against phishing after personal information was stolen from one of its third-party IT providers. The German retail giant, owned by Schwarz Group, said its online shop system itself was not compromised, but a separately stored customer file held by a supplier was accessed and partly exfiltrated by unidentified attack",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What HappenedWhat Data Was ExposedWhy This MattersThe Offline AlternativeKey TakeawaysMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 14 July 2026 

# Lidl Warns Customers After Third-Party IT Provider Breach

Lidl has warned online shoppers in Germany, Belgium and the Netherlands that names, phone numbers, email addresses and dates of birth were stolen from a third-party IT provider. The breach is a fresh reminder that supplier risk is customer risk.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Flidl-third-party-it-provider-data-breach)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Flidl-third-party-it-provider-data-breach&text=Lidl%20Warns%20Customers%20After%20Third-Party%20IT%20Provider%20Breach%0A%0ALidl%20has%20warned%20online%20shoppers%20in%20Germany%2C%20Belgium%20and%20the%20Netherlands%20that%20names%2C%20phone%20numbers%2C%20email%20addresses%20and%20dates%20of%20birth%20were%20stolen%20from%20a%20third-party%20IT%20provider.%20The%20breach%20is%20a%20fresh%20reminder%20that%20supplier%20risk%20is%20customer%20risk.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Flidl-third-party-it-provider-data-breach)[](mailto:?subject=Lidl%20Warns%20Customers%20After%20Third-Party%20IT%20Provider%20Breach&body=Lidl%20has%20warned%20online%20shoppers%20in%20Germany%2C%20Belgium%20and%20the%20Netherlands%20that%20names%2C%20phone%20numbers%2C%20email%20addresses%20and%20dates%20of%20birth%20were%20stolen%20from%20a%20third-party%20IT%20provider.%20The%20breach%20is%20a%20fresh%20reminder%20that%20supplier%20risk%20is%20customer%20risk.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Flidl-third-party-it-provider-data-breach)

![Stylised supermarket receipt dissolving into digital particles with a phishing hook, symbolising the Lidl third-party data breach.](/__l5e/assets-v1/7e282b00-eb5e-43e3-affb-4432248059cf/lidl-third-party-breach-20260714-2x.jpg)

Stylised supermarket receipt dissolving into digital particles with a phishing hook, symbolising the Lidl third-party data breach.

Why it matters

## What this means for organisations holding critical data

Lidl has warned online shoppers in Germany, Belgium and the Netherlands that names, phone numbers, email addresses and dates of birth were stolen from a third-party IT provider. The breach is a fresh reminder that supplier risk is customer risk.

In this analysis

1.  01 [What Happened](#section-0)
2.  02 [What Data Was Exposed](#section-1)
3.  03 [Why This Matters](#section-2)
4.  04 [The Offline Alternative](#section-3)

**On this page**[What Happened](#section-0)[What Data Was Exposed](#section-1)[Why This Matters](#section-2)[The Offline Alternative](#section-3)

Lidl has told customers across Germany, Belgium and the Netherlands to be on guard against phishing after personal information was stolen from one of its third-party IT providers. The German retail giant, owned by Schwarz Group, said its online shop system itself was not compromised, but a separately stored customer file held by a supplier was accessed and partly exfiltrated by unidentified attackers.

## What Happened

According to notifications sent to Belgian and Dutch customers, Lidl became aware of the incident in the week preceding disclosure. The retailer stated that "despite high IT security standards, unidentified individuals were briefly able to access a separately stored file containing customer data and steal some of it." The stolen file related to Lidl online store accounts.

The IT service provider responsible for the file reacted immediately to restore the security of the affected systems and engaged forensic experts to investigate. Relevant data protection authorities have also been notified in line with GDPR obligations.

## What Data Was Exposed

Lidl confirmed the stolen dataset includes:

-   Full names
-   Phone numbers
-   Email addresses
-   Dates of birth
-   Customer numbers

The retailer has ruled out exposure of passwords, billing and delivery addresses, bank details or other payment information. Customer accounts themselves have not been compromised. However, the combination of name, contact details and date of birth is enough to power highly convincing phishing and identity theft attempts.

## Why This Matters

This is a supplier-side breach, not a Lidl platform compromise, and that distinction is the whole story. The largest grocery chain in Europe carries out its due diligence, yet a file held by an external processor was still reached by attackers. Every organisation that trusts a supplier with a [customer database](/oss-for-customer-databases) inherits that supplier's weakest control.

Boris Cipot, principal security engineer at Black Duck, praised the retailer for its speed and candour but noted that the real test is what happens next: how quickly the forensic investigation completes, how clearly Lidl communicates updates, and how rigorously it reassesses the security requirements placed on its service providers going forward.

Under GDPR, retailers remain the data controllers even when the breach happens at a processor. Regulators in Germany, Belgium and the Netherlands will judge Lidl on the strength of its supplier oversight, not on the wording of the contract.

## The Offline Alternative

Every third-party breach follows the same pattern. A file has to sit somewhere reachable so that an application, an analyst or an integration can query it, and once it is reachable it is at risk. Firevault takes the opposite approach for the data that never needs to be queried in real time.

Firevault provides Layer 1 [physical air gap](/how-it-works/offline-secure-storage) storage. The vault is only connected to a network during a scheduled, human-authorised window. Outside that window there is no route in, no cable, no session and no credential that can reach the data. A supplier compromise, a stolen token or an exposed API key cannot pull records out of a device that is not on the wire.

For customer archives, backups of production databases, historical order records, KYC evidence and any dataset held for compliance rather than daily operations, physical disconnection removes the class of attack that hit Lidl's supplier. The file cannot leak from a system that cannot be reached.

## Key Takeaways

-   **Supplier risk is customer risk.** Lidl's own platform held. The breach came through a third-party processor, and the retailer still owns the incident under GDPR.
-   **Contact details plus date of birth is a phishing kit.** Attackers do not need passwords when they have enough context to impersonate a bank, a delivery firm or Lidl itself.
-   **Speed and candour matter.** Lidl notified affected customers and regulators quickly, which is now the baseline expectation for European retailers.
-   **Cold data belongs off the network.** Data held for archive or compliance does not need to be online. [Air gap storage](/how-it-works/offline-secure-storage) removes the attack surface that supplier breaches rely on.

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.infosecurity-magazine.com/news/lidl-notifies-customers-of/)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)[

![Adobe Commerce attacked immediately after session breach vulnerability](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png)

Breach Analysis 

### Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

14 Aug 2026 4 min 







](/news/adobe-commerce-session-vulnerability-exploited-after-disclosure)[

![Cornelius faces legal investigation after alleged Cl0p cyber attack](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/cornelius-alleged-clop-ransomware-data-breach-1786684482605.png)

Breach Analysis 

### Cornelius faces legal investigation after alleged Cl0p cyber attack

Cornelius faces legal scrutiny following reports of a Cl0p ransomware breach in August 2026. Claims suggest thousands of gigabytes of corporate data were compromised.

14 Aug 2026 4 min 







](/news/cornelius-alleged-clop-ransomware-data-breach)[

![Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fdelta-rogue-wifi-defcon-2026.jpg)

Breach Analysis 

### Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust

Delta Air Lines is investigating an unauthorised Wi-Fi network broadcast aboard Flight 591 from Las Vegas to Atlanta, alongside a deauthentication attack that knocked passengers off the aircraft network. The lesson is not about aviation. It is about how easily a trusted connection can be impersonated.

13 Aug 2026 4 min 







](/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026)[

![Ransomware Attacks Spike 20% in July While AI Steals the Headlines](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fransomware-spike-ai-distraction.jpg)

Breach Analysis 

### Ransomware Attacks Spike 20% in July While AI Steals the Headlines

Ransomware attacks jumped nearly 20 per cent in July, with 799 incidents logged globally. While AI dominates security headlines, finance, technology, pharmaceutical, medical billing and education organisations absorbed the sharpest increases.

12 Aug 2026 4 min 







](/news/ransomware-attacks-spike-july-2026-ai-distraction)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)