2026 Inditex — third-party hosted transaction databases (Zara group; Apr)
Data compromised
Commercial transaction relationship metadata per company—no names/phones/cards per Inditex statement
Technical writeup
In mid-April 2026, Inditex (Zara, Bershka, Pull&Bear, Massimo Dutti, and related brands) publicly acknowledged unauthorized access to databases operated by a former or external technology provider affecting multiple international retailers, including Inditex. Spanish and trade reporting described exposure of commercial transaction–relationship data while Inditex stated that categories such as customer names, phones, addresses, passwords, and payment-card data were not part of the affected fields as characterized in its disclosures. The group said its own core retail systems were not compromised and that it activated security protocols and regulatory notifications.
Root cause
Unauthorized access at third-party technology provider infrastructure (per Inditex and press)
References
- https://fashionunited.uk/news/business/inditex-suffers-cyberattack/2026041687507
- https://www.lavanguardia.com/economia/20260415/11514570/inditex-sufre-ataque-informatico-bases-datos.amp.html
- https://www.outlookbusiness.com/deeptech/tech/zara-parent-inditex-reports-third-party-data-breach-involving-transaction-records