EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-zara-data-breach
043/430

File EL-0388HighResolvedData Breach / Data Exfiltration

Zara Data Breach

Also filed as Zara Customer Data Leak · Inditex Breach 2026

Hackers breached the databases of Spanish fast-fashion retailer Zara, stealing data belonging to over 197,000 customers.

  • #retail
  • #fashion
  • #pii
  • #customer-data
  • #spain
Notoriety7/10
Event
1 Apr 2026
Disclosed
8 May 2026
Target
Zara
Scale
197K people
Status
Resolved

01Summary

In April 2026, attackers gained unauthorized access to Zara's customer databases and exfiltrated 197,400 records. The stolen data included customer names, email addresses, phone numbers, and order histories. The breach was confirmed by Have I Been Pwned on May 8, 2026. Zara confirmed the incident and stated that payment card information was not compromised.

02Background

Zara is one of the world's largest fashion retailers, operating over 2,000 stores in 96 countries as part of the Inditex Group.

03Technical analysis

The exact access method was not publicly disclosed. The breach targeted customer databases, suggesting server-side compromise or credential access.

Attack vector
Unknown database compromise
Attack method
Data exfiltration
Exfiltration
Bulk data extraction

04Threat actor

Unknown threat actors.

Attribution sources

  • Have I Been Pwned
  • Zara statements

05Victims and impact

Countries affected

  • Global

06Data exposed

Data types

  • PII
  • Names
  • Email addresses
  • Phone numbers
  • Order histories

07Timeline

  1. 2026-04-01Approximate date of breach.
  2. 2026-05-08Breach listed on HIBP (197,400 records).

08Reaction and fallout

Public reaction

Concern among global customers about retail data security.

09Legal

Potential GDPR investigation.

10Significance and legacy

Significance

Highlights continued data security challenges in global fast-fashion retail.

11Disclosure and media

Authentication
Zara confirmation and HIBP listing

Publishing organisations

  • BleepingComputer
  • Have I Been Pwned

12Field notes

  1. 01Zara operates over 2,000 stores in 96 countries under the Inditex Group.

13Resolution

Zara confirmed the breach and notified affected customers.

14Sources

Official documents

  • Zara data breach notification

References

  1. [1]BleepingComputer: Zara data breach coverage
  2. [2]Have I Been Pwned - Zara listing
Fact sheetEL-0388

Dates

Event
1 Apr 2026
Started
1 Apr 2026
Discovered
1 Apr 2026
Disclosed
8 May 2026
Ongoing
No

Target

Organisation
Zara (Inditex Group)
Type
Retail Company
Sector
Fashion Retail
Country
Spain

Actor

Motivation
Financial gain through sale of stolen customer data.
Attribution
Low
Arrested
No
Convicted
No

Data

People
197,400
Records
197,400
Sensitivity
High
Published
Yes
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.