kompas

Lidl customer data leak: incident details and phishing risks

Editor-in-Chief
12/07/2026

The retail chain Lidl has officially reported a cyber incident that resulted in a leak of personal data of online store customers. The problem affected several European countries, including Slovakia. The company has already started sending warning letters to those whose data may have fallen into the hands of attackers.

The incident did not happen in Lidl's own systems, but in those of one of its external IT suppliers. Hackers briefly gained access to a separate file with customer data and were able to copy part of the information. The company assures that Lidl's own online store systems were not compromised.

What Data Leaked and What is Safe

According to the company's statement, attackers gained access to so-called basic customer data. This set of information is sensitive enough to create risks for users.

What fell into the hackers' hands:

  • Salutation, first name, and last name.
  • Email address.
  • Phone number.
  • Date of birth.
  • Customer number in the Lidl system.

At the same time, Lidl emphasizes that the most critical data remained safe. The leak did not affect passwords, payment information (bank card details), invoices, or delivery addresses. Customer accounts in the online store were not hacked.

The Main Danger is Phishing

Although payment data was not compromised, cybersecurity experts warn that the main threat now lies in targeted phishing attacks. With your name, last name, date of birth, phone number, and even customer number in hand, fraudsters can create extremely convincing emails or SMS messages.

For example, they might send a message supposedly from Lidl asking you to confirm your account details, click a link to get a special discount, or resolve a non-existent problem with an order. Such messages will look very plausible because they will contain your real personal data. The goal of such attacks is to trick you into revealing passwords, payment card details, or other confidential information.

What Lidl Customers Should Do

If you are a customer of the Lidl online store, you should take preventive security measures.

  1. Check your email. Lidl is informing affected customers by email. If you received such a letter, it confirms that your data was in the compromised file.
  2. Be extremely careful. In the coming months, be suspicious of any emails, SMS, or messenger messages that supposedly come from Lidl.
  3. Do not click on links. Never click on links or download attachments from suspicious emails. If you need to log into your Lidl account, always type the website address manually in your browser.
  4. Never share your passwords. Remember that Lidl or any other reliable company will never ask for your password by email or phone.

The incident is international: besides Slovakia, Lidl customers in the Czech Republic, Germany, Belgium, and the Netherlands received similar warnings. According to the portal Skript.sk, citing DSL.sk, the IT supplier where the leak occurred has already filed a police report and involved cybersecurity experts in the investigation.

Sources

Latest news