01Summary
In April 2026, attackers gained unauthorized access to Zara's customer databases and exfiltrated 197,400 records. The stolen data included customer names, email addresses, phone numbers, and order histories. The breach was confirmed by Have I Been Pwned on May 8, 2026. Zara confirmed the incident and stated that payment card information was not compromised.
02Background
Zara is one of the world's largest fashion retailers, operating over 2,000 stores in 96 countries as part of the Inditex Group.
03Technical analysis
The exact access method was not publicly disclosed. The breach targeted customer databases, suggesting server-side compromise or credential access.
- Attack vector
- Unknown database compromise
- Attack method
- Data exfiltration
- Exfiltration
- Bulk data extraction
04Threat actor
Unknown threat actors.
Attribution sources
- Have I Been Pwned
- Zara statements
05Victims and impact
Countries affected
- Global
06Data exposed
Data types
- PII
- Names
- Email addresses
- Phone numbers
- Order histories
07Timeline
- 2026-04-01Approximate date of breach.
- 2026-05-08Breach listed on HIBP (197,400 records).
08Reaction and fallout
Public reaction
Concern among global customers about retail data security.
09Legal
Potential GDPR investigation.
10Significance and legacy
Significance
Highlights continued data security challenges in global fast-fashion retail.
11Disclosure and media
- Authentication
- Zara confirmation and HIBP listing
Publishing organisations
- BleepingComputer
- Have I Been Pwned
12Field notes
- 01Zara operates over 2,000 stores in 96 countries under the Inditex Group.
13Resolution
Zara confirmed the breach and notified affected customers.
14Sources
Official documents
- Zara data breach notification
References
- [1]BleepingComputer: Zara data breach coverage
- [2]Have I Been Pwned - Zara listing









