CTIPilot

Inditex (Zara) breach

incident · incident:inditex-zara-breach-2026

ShinyHunters third-party analytics breach at Inditex (Zara), 197,400 EU customers.

Coverage timeline
1
first 2026-05-09 → last 2026-05-09
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
0
no mapped behavior yet

Hunting pivots

Story timeline

  1. 2026-05-09Inditex (Zara), ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise
    active-threats

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com1 (50%)
  • securityaffairs.com1 (50%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Inditex (Zara) breach (1)

2026-05-09 · view entry permalink →

NOTABLE

Inditex (Zara), ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise

Have I Been Pwned confirmed on 2026-05-08 that 197,400 unique email addresses from Inditex (Zara's parent, headquartered in A Coruña, Spain) were exposed following a breach of a former third-party analytics provider. Inditex confirmed attackers accessed customer relationship data, email addresses, geographic locations, purchase history (order IDs and product SKUs), and support ticket content, across international markets (SecurityAffairs, 2026-05-08 · BleepingComputer, 2026-05-08). Names, passwords, payment card data, addresses, and phone numbers were stated to be out of scope. ShinyHunters claimed responsibility, alleging access via compromised authentication tokens for the Anodot analytics platform against BigQuery instances; this claim has not been independently verified. Data publication (approximately 140 GB) followed after Inditex declined to engage. Inditex stated it had "started notifying the relevant authorities" but did not specify which supervisory authority or whether the GDPR Article 33 72-hour notification clock was met; as a Spanish company the lead supervisory authority is the AEPD.

incident09 May 05:00Zmulti-sourceOpen finding ↗