Summary
- Environment: Inditex statement reported by El País; the exact database owner, platform, access mechanism, and timing were not disclosed.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
A verified HIBP corpus containing unique email addresses and support, order, product, and market fields; Inditex’s contemporaneous statement disputed personal-data impact. [1]
A cited record reports 197,376 records (Unique email addresses in HIBP’s verified corpus; not an Inditex-confirmed affected-person, customer, account, support-ticket, order, or total-row count; as of 2026-05-08). [1]
Inditex said the incident originated with a former technology provider that affected multiple international companies and that Inditex operations and systems were not affected. [2]
Timeline
Public disclosure
Publication date of El País’s report carrying Inditex’s statement; HIBP also uses April 15 as its BreachDate.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Inditex said unauthorized access occurred to company databases hosted on a third party’s servers. [2]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
HIBP marked the Zara incident record verified and not fabricated. Inditex said the databases contained information about commercial relationships with customers in different markets but did not contain names, phone numbers, home addresses, passwords, bank cards, or other payment methods, and it initially ruled out personal-customer-data impact. Inditex said it immediately applied its security protocols and reported the incident to the relevant authorities. The evidence ledger retains 3 disputed claims with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]
