[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fH-SZ1ZJT2yBhGsTVCxTRuZJlNka3acZADKYLknem7J8":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":25,"source":26,"isVerified":4,"isSpamList":27,"isSensitive":4,"severity":28,"processingStatus":29,"logoUrl":30,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66965a9a07ce1db34e9518","LidlOnlineShop2026","Lidl 2026 Online Mağaza Data Breach","lidl-online-shop-2026","lidl.com",{"name":12,"sector":13,"country":14,"website":10},"Lidl","Retail","Germany","2026-07-13T00:00:00.000Z","2026-07-26T23:20:58.248Z",0,[19,20,21,22,23,24],"Salutations","Names","Phone numbers","Email addresses","Dates of birth","Customer numbers","\u003Cp>\u003Cstrong>The Lidl 2026 online-shop data breach\u003C\u002Fstrong> is a confirmed incident in which information belonging to some Lidl online-shop customers in Germany, Belgium, and the Netherlands was stolen following a security event at an IT service provider. Lidl's official customer notices say unidentified people briefly gained unauthorized access to a separately stored file containing customer data and stole part of it. The online-shop system itself was not affected.\u003C\u002Fp>\n\u003Cp>Lidl's notices for Belgium and the Netherlands are primary sources, while BleepingComputer independently reported the disclosures and a response from a company spokesperson. The stolen fields were salutation, first and last name, telephone number, email address, date of birth, and customer number. Lidl explicitly said passwords, billing and delivery addresses, bank details, and other payment information were not affected and customer accounts were not compromised.\u003C\u002Fp>\n\u003Ch2>Confirmed Stolen Data\u003C\u002Fh2>\n\u003Cp>The official notices enumerate six data classes: salutation, first and last names, telephone numbers, email addresses, dates of birth, and customer numbers. These were details belonging to online-shop customers. Lidl said a portion of the data in the file was stolen rather than saying the entire file was taken, but it did not explain which fields existed for each person or whether every recipient had the same combination.\u003C\u002Fp>\n\u003Cp>The affected-person count, file size, and stolen-record total were not published. Lidl's overall customer, employee, or store counts do not measure this incident. LeakData therefore keeps pwnCount at zero, meaning an unknown total. Unless a reliable count is released, general figures describing the scale of the company cannot be converted into the number of breach records.\u003C\u002Fp>\n\u003Ch2>Fields Reported as Unaffected\u003C\u002Fh2>\n\u003Cp>Lidl said that passwords, billing addresses, delivery addresses, bank details, and other payment information could be excluded from the incident at that time. The company also said the online-shop system was not breached and customer accounts were not compromised. Those boundaries distinguish access to a separately stored file at a service provider from mass account access to Lidl's direct e-commerce platform.\u003C\u002Fp>\n\u003Cp>The “not affected” finding should be applied only to the fields the company excluded. This record does not add passwords as a data class or claim that attackers used customer accounts because password exposure was not confirmed. However, a stolen combination of names, dates of birth, phone numbers, and email addresses can still support personalized phishing. Excluding payment data does not eliminate every social-engineering risk.\u003C\u002Fp>\n\u003Ch2>Timing and the Third Party\u003C\u002Fh2>\n\u003Cp>Lidl's customer notices say the company was informed of the incident at the beginning of the week, but they do not provide the exact dates of initial access, theft, or discovery. BleepingComputer reported on July 13, 2026 that customers had been notified the previous week. July 13 is used in LeakData as a verified public-disclosure reference; it is not a claim that the attacker first entered the service provider's file that day.\u003C\u002Fp>\n\u003Cp>The company did not identify the affected IT provider, the system hosting the file, the attack method, or the exact duration of unauthorized access. The notice confirms only that access was brief and a portion of the data in a separately stored file was stolen. The third-party location does not remove Lidl from the record: the stolen information belonged to Lidl customers and Lidl issued the notifications.\u003C\u002Fp>\n\u003Ch2>Response and Official Notifications\u003C\u002Fh2>\n\u003Cp>According to Lidl, the IT service provider responded immediately and took the necessary steps to restore full security to the affected systems. The provider also filed a police complaint and promptly engaged IT forensic specialists to investigate. Lidl notified the competent data-protection authorities, and the news report specifically notes notification of the Dutch Data Protection Authority.\u003C\u002Fp>\n\u003Cp>The company said it had no concrete evidence of data misuse at the time of notice. That statement does not mean no data was stolen; the theft itself is confirmed and the statement only limits observed misuse. Lidl warned affected customers as a precaution about possible phishing and identity abuse, recommending that they verify unexpected senders, avoid sharing data, and not click unknown links.\u003C\u002Fp>\n\u003Ch2>Practical Steps for Customers\u003C\u002Fh2>\n\u003Cp>Affected customers should be cautious of messages impersonating Lidl, a parcel carrier, or a payment company and using a date of birth, customer number, or telephone detail to appear credible. Requests to open a link for an order problem, refund, coupon, delivery fee, or account verification can be checked independently through Lidl's official site or a known support channel. Use of real personal details does not prove a message is legitimate.\u003C\u002Fp>\n\u003Cp>Lidl reported that passwords were unaffected, so this incident does not support a claim that password resets are mandatory. Customers can still replace reused or previously exposed passwords with unique ones as general protection. Suspicious calls and emails can be preserved and reported through Lidl's official data-contact channels. People who received no notice should not assume involvement solely because they used the shop and can seek case-specific confirmation.\u003C\u002Fp>\n\u003Ch2>How to Interpret This LeakData Record\u003C\u002Fh2>\n\u003Cp>This is not an account breach of Lidl's online-shop platform; it is data theft from a separately stored customer file at an IT service provider. A zero affected-person value means no verified total was published, not that nobody was affected. The data classes contain only the six fields listed in the official notice and do not include the explicitly excluded passwords, addresses, bank details, or payment information.\u003C\u002Fp>\n\u003Cp>The verified conclusion is that unidentified people briefly accessed a separate provider file and stole some Lidl online-shop customer data; salutations, names, phone numbers, email addresses, dates of birth, and customer numbers were involved; and the shop, accounts, passwords, and payment details were unaffected. Exact timing, access method, and person count remain undisclosed. LeakData presents the incident within those evidentiary limits.\u003C\u002Fp>","Third-party IT service provider breach",false,"Low","completed","\u002Fuploads\u002Flogo\u002Flidl_com.svg"]