Retailers Expose Customer Data Through Vendors
Coverage from The Record, BleepingComputer, and others
Articles
14
Active Days
128
The Topic

Retail and outsourcing organizations disclosed breaches in which attackers accessed customer or business data through external providers, connected systems, or portions of corporate networks. The Lidl and Loblaw incidents primarily exposed contact and identifying information while reportedly leaving payment credentials and passwords unaffected; Telus Digital reported unauthorized access while investigating a much larger theft claim made by ShinyHunters. The incidents highlight how vendor access and interconnected cloud environments can expand exposure, while affected organizations often lack confirmed information about the number of records, data scope, or attacker identity.
First Article: 03/12/26
Latest Article: 07/17/26
Summary
- Lidl reported that an external IT provider was breached, exposing online-shop customer names, contact details, dates of birth, and customer numbers in Germany, Belgium, and the Netherlands.
- Lidl said passwords, addresses, bank details, payment information, and the online shop itself were not compromised, although the exposed data could support targeted phishing.
- Loblaw disclosed unauthorized access to a contained part of its IT network that exposed names, phone numbers, and email addresses; it said payment, health, and password data were not affected.
- Telus Digital confirmed unauthorized access to several systems while investigating ShinyHunters’ claim that nearly 1 petabyte of customer and corporate data was stolen.
- The Telus incident illustrates the potential reach of compromised cloud credentials and interconnected systems, including Salesforce, Google Cloud, BigQuery, call records, support data, and source code.
- Across the incidents, affected organizations secured systems, notified authorities or law enforcement, and continued investigations, but several key scope and attribution details remained undisclosed.
History
The main update is a reframing of the Telus Digital incident: the claim is now attributed to ShinyHunters and the alleged theft is described as nearly 1 petabyte of customer and corporate data, although that scale remains unverified. The rest of the story is largely a clarification of already reported breach impacts and response activity.
The story has broadened from a largely Lidl-centered vendor breach to a wider multi-organization incident set, with Loblaw and especially Telus Digital adding a new corporate-data-theft angle. The Telus case is the biggest new development because it introduces unverified but large-scale theft claims and a named threat actor, shifting the focus from exposed customer contact data to potentially extensive enterprise compromise.
