← Blog

Inditex: Third-Party Transaction Database Incident (Zara)

Share on X

Mid–April 2026 statements from Inditex described unauthorized access to transaction-oriented databases hosted with a third-party technology provider, with parallel coverage noting other retailers using the same ecosystem. Public messaging emphasized that Inditex’s own core systems stayed operational and framed the affected data as commercial relationship / transaction metadata rather than direct payment-card or full identity dossiers.

Canonical record: Inditex 2026 on BreachHistory.

Sources: FashionUnited, La Vanguardia