Lidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data Breach

2026-07-14T02:51:39Zf6558205816b327989d7815e25efdadad88a1c668e95a513a01ddae4bbdab1bc
cisacms-exploitationcve-2008-4128data-breachfsbincident-responsejoomlakevknown-exploited-vulnerabilitiesodidophishingransomwareryuksanctionssharefilestorage-zonesupply-chainthird-party-breachwebshellwordpress

What happened

Multiple security incidents and alerts: Lidl notified online-shop customers in Germany, Belgium and the Netherlands that personal data was stolen in a breach of a third‑party IT provider (payment data not exposed). CISA added Cisco IOS flaw CVE-2008-4128 to its Known Exploited Vulnerabilities catalog and also added other CMS-related flaws (iCagenda, Balbooa Forms) to KEV. Australia warned of a large-scale campaign actively exploiting CMS vulnerabilities (WordPress, Joomla, etc.) to deploy webshells. Dutch police link local suspects to the Odido breach that exposed data on ~6 million customers;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f6558205816b327989d7815e25efdadad88a1c668e95a513a01ddae4bbdab1bc
Enrichment time
2026-07-14T02:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.