← Blog

Zara: 197K Rows in ShinyHunters-Linked Supply Chain Wave

Share on X

Zara—flagship apparel label of Spain’s Inditex—captured headlines when breach intelligence services enumerated roughly 197,000 compromised customer artefacts tracing to an April 2026 incident cluster described upstream as stemming from weakened third-party/analytics tooling rather than in-store terminals.

Consumer guidance should assume e-commerce footprints (order IDs, unique emails, SKU-level shopping analytics, help-desk artefacts) circulate in phishing kits even while parent statements stressed no live payment PAN data exfiltration. BreachHistory tracks the enumerated figure from HIBP corroborating trade coverage and cautions shoppers that hyperbolic 95 M‑class ticket tables remain uncorroborated next to presently indexed denominators.

Canonical record: Zara 2026 supply-chain incident on BreachHistory.

Sources: Infosecurity Magazine, Have I Been Pwned