The well-known German chain Lidl has been hacked. Lidl itself announced this, having warned its customers that part of the loot consists precisely – as we will detail shortly – of user data.
WHAT WE KNOW ABOUT THE DATA THEFT AT LIDL
According to established practice, the hackers did not target the well-known brand directly, but an external supplier. At present, from the initial reconstructions of the incident, it appears that the breach concerns only customers of the supermarket chain in Germany, Belgium, and the Netherlands. Currently, there is no evidence to suggest that the breach may also involve data of Italian users, where the discount chain is widely present. As mentioned above, Lidl has already contacted all affected individuals by email and published notices on its local official channels.
WHAT THE HACKERS STOLE
The breach led to the theft of some data from online store customers: no credit cards or credentials, but ancillary information such as first name, last name, phone number, email address, date of birth, and customer number. The attack was discovered only last week, and the IT service provider reported it to the competent authorities, who have opened an investigation.
It is learned that, in addition to the usual procedures, such as alerting the Dutch Data Protection Authority as required by European consumer protection regulations, a forensic IT team was also engaged to understand the exact scope of the attack and assess the consequences of the breach.
WHY SUCH LOOT IS APPEALING TO HACKERS
Often this loot, although seemingly not very lucrative, is still attractive to hackers (both those who carry out the theft and other groups who might decide to buy the stolen goods) because it allows sending targeted phishing emails or SMS: in other words, fake communications are created in the name of the service where the user is registered, containing information not publicly available (such as the customer number), persuading the victim to click on a fake link that could, for example, install malware on their device.
It should be clarified, however, that the investigations are not yet concluded and there is no certainty about the exact scope of the theft: it is not excluded that the hackers may have stolen other material, possibly more alarming, such as passwords of users who log in online, billing and delivery addresses, bank details, or other payment-related data.




