← Inditex

2026 Inditex — third-party hosted transaction databases (Zara group; Apr)

2026 Unknown records affected Share on X

Data compromised

Commercial transaction relationship metadata per company—no names/phones/cards per Inditex statement

Technical writeup

In mid-April 2026, Inditex (Zara, Bershka, Pull&Bear, Massimo Dutti, and related brands) publicly acknowledged unauthorized access to databases operated by a former or external technology provider affecting multiple international retailers, including Inditex. Spanish and trade reporting described exposure of commercial transaction–relationship data while Inditex stated that categories such as customer names, phones, addresses, passwords, and payment-card data were not part of the affected fields as characterized in its disclosures. The group said its own core retail systems were not compromised and that it activated security protocols and regulatory notifications.

Root cause

Unauthorized access at third-party technology provider infrastructure (per Inditex and press)

References