← Zara

2026 Zara (Inditex) — ShinyHunters/Anodot supply-chain breach; 197.4k emails in HIBP (95M ticket rows claimed)

2026 197.4K records affected Share on X

Data compromised

Email addresses, geographic markets, purchase/order IDs, product SKUs, and customer-support ticket metadata per HIBP and Inditex; passwords and payment data not affected per company statement

Technical writeup

Verified breach — April–May 2026. ShinyHunters targeted Zara as part of an April 2026 pay-or-leak campaign, claiming compromise via the Anodot analytics platform and publishing roughly a terabyte of data including an alleged 95 million customer-support ticket rows. Parent company Inditex publicly acknowledged the third-party incident and stated passwords and payment information were not affected. Have I Been Pwned loaded the breach on May 8, 2026, indexing 197,400 unique email addresses alongside product SKUs, order IDs, markets, and support-ticket metadata. BreachHistory uses the HIBP-verified 197.4k email count; ShinyHunters' 95M ticket-row marketing figure remains uncorroborated as a distinct victim denominator. In July 2026, DarkForums user Blastoize reposted the dataset with HIBP context and sample ticket CSV fields.

Root cause

ShinyHunters extortion via alleged Anodot analytics-platform compromise; third-party cloud/analytics supply-chain access

References