ConfirmedData breach
Zara: a data breach
In April 2026, the fashion brand Zara was among a number of organisations targeted by the ShinyHunters extortion group as part of their "pay or leak" campaign. The group claimed the breach was related to a compromise of the Anodot analytics platform and subsequently published a terabyte of data allegedly including 95M support ticket records. The data contained 197k unique email addresses alongside product SKUs, order IDs and the market the support ticket originated in. Zara's parent company Inditex advised that the incident didn't affect passwords or payment information .
The record
- Organisation
- Zara →
- Identity
- Zaraidentified by its domain in a verified breach record
- Records affected
- 197,376 records
- Data exposed
- Email addresses, Geographic locations, Purchases, Support tickets
- Sector
- Not recorded
- Occurred
- 2026-04-15
- Disclosed
- 2026-05-08
- First recorded here
- 2026-09-09
Sources (1)
One source so far.
- Have I Been Pwned ↗First reported
2026-05-08