top of page

Stay Ahead of Emerging Threats

Thanks for submitting!

ESET Nigeria Highlights Third-Party Cybersecurity Risks Following Lidl Data Breach

  • Writer: ESET Expert
    ESET Expert
  • 2 days ago
  • 3 min read

Updated: 1 day ago

Cybersecurity experts urge organisations to strengthen third-party risk management and remain vigilant against phishing attacks after the retailer disclosed a data breach involving an external service provider.


PR LAGOS, Nigeria – 14 July 2026 – ESET Nigeria has called on organisations to strengthen third-party cybersecurity practices and reinforce customer awareness following Lidl's disclosure of a data breach linked to one of its external service providers.




According to Lidl, the incident affected customers who used its online shop in Germany, Belgium and the Netherlands. Information reportedly exposed includes customers' names, telephone numbers, email addresses, dates of birth and customer identification numbers. The retailer stated that passwords, payment card details, banking information and login credentials were not compromised, adding that its own internal systems were unaffected.


Although the breach occurred outside Nigeria, ESET Nigeria says the incident reflects a growing global cybersecurity challenge. As businesses increasingly depend on third-party vendors for cloud services, payment processing, logistics, customer relationship management and digital communications, cybercriminals are exploiting weaknesses across entire supply chains rather than targeting organisations directly.


"Cybersecurity is no longer defined solely by how well an organisation protects its own infrastructure. Increasingly, the security posture of every third-party provider has become an extension of an organisation's own cybersecurity resilience.Incidents such as this demonstrate that even when an organisation's internal systems remain secure, a compromise affecting a trusted service provider can still expose customer information and create opportunities for cybercriminals to exploit public trust. Organisations must therefore treat third-party cybersecurity as a critical component of their overall risk management strategy."
Olabanji Soledayo, ESET Nigeria.

Following breaches involving customer information, cybercriminals frequently launch highly targeted phishing campaigns designed to exploit uncertainty and public concern. Fraudulent emails, SMS messages and fake customer notifications often imitate trusted brands, encouraging recipients to click malicious links, verify account information or disclose sensitive personal details.


"One of the greatest risks following a data breach is not always the breach itself, but the phishing campaigns that often follow," Soledayo added.


"Threat actors understand that customers are more likely to trust communications appearing to come from familiar brands immediately after a publicly disclosed incident. This creates an opportunity for convincing phishing attacks that can lead to credential theft, identity fraud or financial loss. Customers should independently verify any unexpected communication before clicking links, downloading attachments or sharing personal information."


Why This Matters for Nigerian Organisations


The Lidl incident serves as an important reminder that cybersecurity risks extend beyond direct attacks on an organisation's own systems. Across Nigeria, businesses increasingly rely on external technology providers for cloud infrastructure, payment services, logistics, marketing platforms, software development, customer support and data management.


While outsourcing can improve operational efficiency, it also introduces additional cybersecurity considerations. A vulnerability affecting a single service provider may have consequences for multiple organisations simultaneously, underscoring the importance of comprehensive vendor risk management.


ESET Nigeria encourages organisations to conduct regular cybersecurity assessments of third-party providers, establish clear security requirements within supplier agreements, implement continuous monitoring where appropriate and develop incident response plans that account for potential supply chain compromises.


Customers are equally encouraged to remain cautious following publicly reported breaches. Unexpected emails, SMS messages or phone calls requesting passwords, one-time passcodes, banking information or personal details should be treated with caution, even if they appear to reference genuine incidents.


Building Cyber Resilience Beyond Organisational Boundaries


As digital ecosystems become increasingly interconnected, cybersecurity must extend beyond organisational perimeters to include partners, vendors and service providers throughout the supply chain.


The Lidl incident highlights a broader reality facing organisations worldwide: maintaining strong internal security controls alone is no longer sufficient. Building cyber resilience requires continuous evaluation of third-party relationships, proactive risk management and ongoing customer awareness to reduce opportunities for cybercriminals to exploit trust.


By combining world-class threat intelligence, cybersecurity research and advanced protection technologies, ESET remains committed to helping organisations strengthen their resilience against evolving cyber threats while promoting safer digital experiences for businesses and consumers alike.


About ESET


For more than 30 years, ESET has been a global leader in cybersecurity, protecting businesses, critical infrastructure and consumers against increasingly sophisticated cyber threats. Leveraging advanced machine learning, cloud-powered threat intelligence and decades of research expertise, ESET delivers proactive, multi-layered security solutions that enable organisations to embrace digital transformation with confidence.


Through ESET Nigeria, the company continues to provide trusted cybersecurity solutions, expert guidance and security awareness initiatives that help organisations and individuals build resilience in an increasingly connected world.


For more information about ESET Nigeria and its cybersecurity solutions, visit www.eset.com/ng.

Tags:

 
 
 

Comments


bottom of page