A cyberattack against Lidl via an external IT provider has resulted in the theft of personal data linked to the company's e-commerce operations. The incident affects customers in Germany, Belgium and the Netherlands and shows how the supply chain has become an increasingly important target for cybercriminals. The incident underlines that the cybersecurity of modern organizations is not only determined by their own infrastructure, but also by the security of external suppliers and partners.
According to Lidl The breach did not occur in the company's own systems, but at an external service provider where a separately stored file with customer information was located. The company states that its own e-commerce platform has not been compromised and that passwords, payment details, banking information and customer accounts are not included in the stolen information.
The cyberattack against Lidl At the same time, it shows how a breach at a third-party supplier can have widespread consequences even when the company's own security solutions are functioning properly.
Personal information has been stolen
The information that Lidl says has been exposed includes:
- First and last name
- Email addresses
- Phone number
- Date of birth
- Customer number
While payment details should not have been leaked, this type of information poses a significant risk. The combination of contact details and customer information can be used to create highly credible phishing emails, fake delivery notifications, offers, and other fraudulent attempts that are difficult to distinguish from legitimate communications.
After the cyberattack against Lidl, Integrity360 warns of phishing
Emil Olofsson, cybersecurity expert at Integrity360, believes that the biggest danger is not necessarily the data leak itself, but what happens after the information ends up in the wrong hands.
“For customers who may have been affected, the biggest risk now is not the data breach itself, but what comes afterwards. Cybercriminals are quick to exploit this type of information to create credible fraud attempts, such as fake delivery notifications, offers or loyalty mailings that look completely genuine.”
He also highlights how the attack illustrates the increasing importance of security in the supply chain.
“When a breach occurs via a supplier, it often becomes an insider security risk in practice. The attack on Lidl shows that a company’s security is only as strong as the weakest link in the supply chain.”
The supply chain has become one of the biggest attack surfaces
In recent years, cybercriminals have increasingly targeted third-party vendors. Instead of trying to break through well-protected corporate networks, they are targeting vendors that handle customer data, operations, cloud services, or mission-critical systems.
A single successful breach at a vendor can impact thousands or even millions of users simultaneously. For companies, this means that security efforts must encompass the entire digital ecosystem, not just their own IT environment.
Lidl urges customers to be vigilant
Lidl says there is currently no confirmed information that the stolen information has been misused. The company is still urging affected customers to to pay extra attention to emails, text messages and phone calls where someone pretends to represent Lidl or other trusted actors.
The company has informed the relevant data protection authorities and is working with IT forensic experts to investigate the incident. The identity of the external IT provider has not yet been made public.
Companies need to strengthen control over external suppliers
The Lidl incident shows how important it is for companies to not only review their own security, but also check how external suppliers store, process and protect customer information.
Security requirements should be clearly regulated in contracts and supplemented by continuous security audits, risk assessments and requirements for rapid incident reporting. Organizations also need full visibility into which subcontractors handle their data and how they work with identity management, access controls, encryption and monitoring.
When information is shared between multiple actors, the risk of a vulnerability outside one's own organization having far-reaching consequences increases. Therefore, supplier governance is becoming an increasingly important part of strategic cybersecurity work.
IT Industry Analysis
The cyberattack against Lidl is another example of how the threat landscape is changing. Cybercriminals are increasingly targeting vendors and service providers where a single breach can provide access to large amounts of information from multiple organizations simultaneously.
For Swedish businesses, the development is particularly relevant in light of regulations that NIS2 and DORA, where third-party risk management and supplier security are taking on an increasingly central role. Companies are expected not only to protect their own systems but also to ensure that external suppliers meet high requirements for information security, incident management and continuity.
The lesson from Lidl is clear. A company can invest significant resources in cybersecurity and still suffer when an external partner becomes the weakest link. For CIOs, security managers and business leaders, this means that supplier risk needs to be treated as a strategic business risk rather than a technical detail.
As organizations become increasingly dependent on cloud services, outsourcing, and digital partnerships, supplier security will become a key competitive factor. The organization that has the best control over its entire digital ecosystem will also be best equipped to meet tomorrow's cyber threats.








