Zara data breach exposed personal information of 197,000 people
Notify stakeholders and review access controls to mitigate exposure.
Notify stakeholders and review access controls.
Summary
Zara, the flagship brand of Inditex, suffered a data breach that exposed personal information of 197,400 customers on May 8, 2026.
Hackers accessed databases hosted by a former technology provider, but no names, phone numbers, addresses, credentials or payment data were compromised. The breach involved unique email addresses, product SKUs, order IDs, and support ticket market information. ShinyHunters claimed responsibility and released a 140 GB archive of stolen data, including documents from BigQuery instances. Inditex applied security protocols, notified authorities, and confirmed operations were unaffected. The incident highlights the risk of third‑party provider vulnerabilities and the importance of monitoring access to customer data.
Key changes
- 197,400 unique email addresses, product SKUs, order IDs, and support ticket market data were exposed.
- No names, phone numbers, addresses, credentials, or payment information were compromised.
- The breach involved databases hosted by a former technology provider, not Inditex’s own infrastructure.
- ShinyHunters claimed responsibility and released a 140 GB archive of stolen data from BigQuery instances.
- Inditex applied security protocols, notified authorities, and confirmed operations remained unaffected.