---
title: "Zara former-provider customer-transaction database incident"
description: "Evidence-backed account of Zara former-provider customer-transaction database incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/zara-former-provider-customer-transaction-database-incident-2026"
markdown_url: "https://www.ally.security/incidents/zara-former-provider-customer-transaction-database-incident-2026.md"
stix_url: "https://www.ally.security/incidents/zara-former-provider-customer-transaction-database-incident-2026/stix.json"
---

# Zara former-provider customer-transaction database incident

Unauthorized access to Inditex databases hosted by a former technology provider and associated by HIBP with Zara. A verified HIBP corpus containing unique email addresses and support, order, product, and market fields; Inditex's contemporaneous statement disputed personal-data impact.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Inditex statement reported by El País; the exact database owner, platform, access mechanism, and timing were not disclosed.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access to Inditex databases hosted by a former technology provider and associated by HIBP with [Zara](https://www.zara.com/). [1](#source-1)

## Impact

A verified HIBP corpus containing unique email addresses and support, order, product, and market fields; Inditex's contemporaneous statement disputed personal-data impact. [1](#source-1)

A cited record reports 197,376 records (Unique email addresses in HIBP's verified corpus; not an Inditex-confirmed affected-person, customer, account, support-ticket, order, or total-row count; as of 2026-05-08). [1](#source-1)

Inditex said the incident originated with a former technology provider that affected multiple international companies and that Inditex operations and systems were not affected. [2](#source-2)

## Timeline

### April 15, 2026 — Public disclosure

Publication date of El País's report carrying Inditex's statement; HIBP also uses April 15 as its BreachDate. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Inditex said unauthorized access occurred to company databases hosted on a third party's servers. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

HIBP marked the Zara incident record verified and not fabricated. Inditex said the databases contained information about commercial relationships with customers in different markets but did not contain names, phone numbers, home addresses, passwords, bank cards, or other payment methods, and it initially ruled out personal-customer-data impact. Inditex said it immediately applied its security protocols and reported the incident to the relevant authorities. The evidence ledger retains 3 disputed claims with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/zara-former-provider-customer-transaction-database-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Zara breach record

advisory · Have I Been Pwned · May 8, 2026

<https://haveibeenpwned.com/api/v3/breach/Zara>

<a id="source-2"></a>

### Inditex sufre un ataque informático con acceso a bases de datos internas

news · El País · Apr 15, 2026

<https://elpais.com/economia/2026-04-15/inditex-sufre-un-ataque-informatico-con-acceso-a-bases-de-datos-de-sus-filiales.html>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Exposed Record Count · 100% confidence · current**  
   Zara support, order, market, and email corpus: 197,376 record
2. **Resulted In · 75% confidence · disputed**  
   April 2026 Inditex and Zara third-party database incident: Zara support, order, market, and email corpus
3. **Subsidiary Of · 100% confidence · current**  
   Zara: Industria de Diseño Textil, S.A.
4. **Exposed Data Category · 80% confidence · disputed**  
   Zara support, order, market, and email corpus: Contact information
5. **Resulted In · 100% confidence · current**  
   Zara support, order, market, and email corpus: HIBP marked the Zara breach record verified and not fabricated.
6. **Resulted In · 95% confidence · current**  
   April 2026 Inditex and Zara third-party database incident: Inditex said the breach originated with a former technology provider that affected multiple international companies and that Inditex operations and systems were not affected.
7. **Affected Organization · 95% confidence · current**  
   April 2026 Inditex and Zara third-party database incident: Zara
8. **Disclosed At · 100% confidence · current**  
   April 2026 Inditex and Zara third-party database incident: 2026-04-15
9. **Resulted In · 95% confidence · current**  
   April 2026 Inditex and Zara third-party database incident: Inditex said the databases contained information about commercial relationships with customers in different markets but did not contain names, phone numbers, home addresses, passwords, bank cards, or other payment methods, and it initially ruled out personal-customer-data impact.
10. **Resulted In · 95% confidence · current**  
   April 2026 Inditex and Zara third-party database incident: Inditex said it immediately applied its security protocols and reported the incident to the relevant authorities.
11. **Resulted In · 95% confidence · current**  
   April 2026 Inditex and Zara third-party database incident: Inditex said unauthorized access occurred to company databases hosted on a third party's servers.
12. **Affected Organization · 100% confidence · current**  
   April 2026 Inditex and Zara third-party database incident: Industria de Diseño Textil, S.A.
13. **Exposed Data Category · 85% confidence · disputed**  
   Zara support, order, market, and email corpus: Customer service records

</details>
