Last Update: 08/01/2026 at 1:00 PM EST

Retailers Expose Customer Data Through Vendors

Coverage from The Record, BleepingComputer, and others

Articles

14

Active Days

128

The Topic

Retailers Expose Customer Data Through Vendors topic image

Retail and outsourcing organizations disclosed breaches in which attackers accessed customer or business data through external providers, connected systems, or portions of corporate networks. The Lidl and Loblaw incidents primarily exposed contact and identifying information while reportedly leaving payment credentials and passwords unaffected; Telus Digital reported unauthorized access while investigating a much larger theft claim made by ShinyHunters. The incidents highlight how vendor access and interconnected cloud environments can expand exposure, while affected organizations often lack confirmed information about the number of records, data scope, or attacker identity.

First Article: 03/12/26

Latest Article: 07/17/26

Summary

  • Lidl reported that an external IT provider was breached, exposing online-shop customer names, contact details, dates of birth, and customer numbers in Germany, Belgium, and the Netherlands.
  • Lidl said passwords, addresses, bank details, payment information, and the online shop itself were not compromised, although the exposed data could support targeted phishing.
  • Loblaw disclosed unauthorized access to a contained part of its IT network that exposed names, phone numbers, and email addresses; it said payment, health, and password data were not affected.
  • Telus Digital confirmed unauthorized access to several systems while investigating ShinyHunters’ claim that nearly 1 petabyte of customer and corporate data was stolen.
  • The Telus incident illustrates the potential reach of compromised cloud credentials and interconnected systems, including Salesforce, Google Cloud, BigQuery, call records, support data, and source code.
  • Across the incidents, affected organizations secured systems, notified authorities or law enforcement, and continued investigations, but several key scope and attribution details remained undisclosed.

History

07/23/2026

The main update is a reframing of the Telus Digital incident: the claim is now attributed to ShinyHunters and the alleged theft is described as nearly 1 petabyte of customer and corporate data, although that scale remains unverified. The rest of the story is largely a clarification of already reported breach impacts and response activity.

07/21/2026

The story has broadened from a largely Lidl-centered vendor breach to a wider multi-organization incident set, with Loblaw and especially Telus Digital adding a new corporate-data-theft angle. The Telus case is the biggest new development because it introduces unverified but large-scale theft claims and a named threat actor, shifting the focus from exposed customer contact data to potentially extensive enterprise compromise.

Full History

Featured

Timeline: 128 Days

Mar 12Apr 9May 7May 21Jun 18Jul 16

Additional Articles

⭐⭐⭐⭐⭐

SC Media07-13-2026
Lidl disclosed a third-party cyberattack on an external IT service provider affecting customers in Germany, Belgium, and the Netherlands early last week.
Techzine07-13-2026
Lidl reported an external IT-provider data breach in the Netherlands, Belgium, and Germany, exposing customer contact details and dates of birth.
Safestate07-14-2026
Lidl notified customers in Germany, Belgium, and the Netherlands after attackers accessed a customer-data file at a third-party IT provider storing Lidl online-shop information.
Security Affairs / Pierluigi Paganini07-13-2026
Lidl notified customers in Germany, Belgium, and the Netherlands about a third-party IT provider breach discovered at the start of the week.
Bitdefender07-15-2026
Lidl disclosed a vendor-related incident affecting Lidl online store customers in Germany, Belgium, and the Netherlands, and issued phishing and identity abuse warnings.
SecurityBoulevard / Deepak Gupta03-30-2026
Panera Bread confirmed a breach after ShinyHunters access and public leakage of about 5.1 million customer accounts, exposing contact data used for long-term fraud risk.
CybelAngel / Orlaith Traynor07-15-2026
Lidl notified customers in Germany, Belgium, and the Netherlands after theft of personal data from a third-party IT provider triggered GDPR-style breach communications.
Rescana03-15-2026
Loblaw disclosed on March 10, 2026 that customer names, phone numbers, and emails were exposed in a data breach in Canada due to unauthorized access.

⭐⭐⭐

Privacy Guides / Nate Bartram07-17-2026
Lidl notified customers in Germany, Belgium, and the Netherlands after a service-provider breach exposed customer names, contact details, and dates of birth.
Restaurant Business Online07-09-2026
VikingCloud reported that a survey of 50 restaurant IT leaders found 78% experienced cyberattacks in 12 months, often exposing payment and customer data.

⭐️⭐️

The Register / Jessica Lyons03-15-2026
Telus Digital reports unauthorized access to limited systems; Starbucks breach affects 889 partners in Maine; Loblaw confirms a data breach.