2026 Zara (Inditex) — ShinyHunters/Anodot supply-chain breach; 197.4k emails in HIBP (95M ticket rows claimed)
Data compromised
Email addresses, geographic markets, purchase/order IDs, product SKUs, and customer-support ticket metadata per HIBP and Inditex; passwords and payment data not affected per company statement
Technical writeup
Verified breach — April–May 2026. ShinyHunters targeted Zara as part of an April 2026 pay-or-leak campaign, claiming compromise via the Anodot analytics platform and publishing roughly a terabyte of data including an alleged 95 million customer-support ticket rows. Parent company Inditex publicly acknowledged the third-party incident and stated passwords and payment information were not affected. Have I Been Pwned loaded the breach on May 8, 2026, indexing 197,400 unique email addresses alongside product SKUs, order IDs, markets, and support-ticket metadata. BreachHistory uses the HIBP-verified 197.4k email count; ShinyHunters' 95M ticket-row marketing figure remains uncorroborated as a distinct victim denominator. In July 2026, DarkForums user Blastoize reposted the dataset with HIBP context and sample ticket CSV fields.
Root cause
ShinyHunters extortion via alleged Anodot analytics-platform compromise; third-party cloud/analytics supply-chain access
References
- https://haveibeenpwned.com/Breach/Zara
- https://hackread.com/shinyhunters-leak-udemy-zara-7-eleven-data-breach/
- https://www.infosecurity-magazine.com/news/zara-data-breach-impacts-200000/
- https://www.outlookbusiness.com/deeptech/tech/zara-parent-inditex-reports-third-party-data-breach-involving-transaction-records
- https://darkforums.ru/Thread-DATABASE-Spain-zara-com-International-Fashion-Company-Support-Ticket-95M-2026