Retailers Expose Customer Data Through Vendors
Coverage from Security Affairs, CybelAngel, and others

Retail and outsourcing organizations disclosed breaches in which attackers accessed customer or business data through external providers, connected systems, or portions of corporate networks.
The Lidl and Loblaw incidents primarily exposed contact and identifying information while reportedly leaving payment credentials and passwords unaffected; Telus Digital reported unauthorized access while investigating a much larger theft claim made by ShinyHunters. The incidents highlight how vendor access and interconnected cloud environments can expand exposure, while affected organizations often lack confirmed information about the number of records, data scope, or attacker identity.
The main update is a reframing of the Telus Digital incident: the claim is now attributed to ShinyHunters and the alleged theft is described as nearly 1 petabyte of customer and corporate data, although that scale remains unverified. The rest of the story is largely a clarification of already reported breach impacts and response activity.
The story has broadened from a largely Lidl-centered vendor breach to a wider multi-organization incident set, with Loblaw and especially Telus Digital adding a new corporate-data-theft angle. The Telus case is the biggest new development because it introduces unverified but large-scale theft claims and a named threat actor, shifting the focus from exposed customer contact data to potentially extensive enterprise compromise.
