Inditex reports unauthorized access to internal databases

Inditex, the textile group behind Zara, disclosed on Wednesday night an unauthorized access to internal databases hosted on a third-party provider's servers. The company states no customer personal data, such as names, phones or credit cards, was compromised. Operations remain fully unaffected.

Inditex notified on Wednesday night of an unauthorized access to databases holding commercial information on clients from various markets. Hosted on a third-party provider's servers, these do not contain sensitive personal data, the company said. "In no case data such as names and surnames, phone, address, passwords, credit cards or other payment methods," the statement specifies.

The firm immediately applied its security protocols and alerted the relevant authorities. The breach stemmed from an issue at a former tech supplier affecting multiple international companies. "Inditex's operations and systems have suffered no disruption and customers can continue accessing and operating securely," the Galician textile group added.

Inditex lists cybersecurity among key risks due to its digital model. It has an information security committee involving top executives like CEO Óscar García Maceiras, and a cybersecurity advisory committee formed in 2023. The latter met five times in 2025 to review threats including AI and new intrusion techniques. It also runs a 24/7 security operations center that identified 66 events in 2025 with no notable impacts.

This is not the first such incident in Spanish retail. In October, Mango disclosed unauthorized access to client marketing data via an external service. El Corte Inglés faced a similar breach in March last year involving data on an external provider.

Связанные статьи

Illustration of ANCI-confirmed cyber infiltration in Chilean public agency due to stolen credentials, featuring hacker screens and government imagery.
Изображение, созданное ИИ

ANCI confirms infiltration in public agency due to stolen credentials

Сообщено ИИ Изображение, созданное ИИ

Chile's Agencia Nacional de Ciberseguridad (ANCI) detected an infiltration in a public agency after a staff member's login credentials were stolen. Security Minister Trinidad Steinert described the alert as delicate and deferred the investigation to ANCI. The issue was resolved by closing accesses, though most circulating data stems from prior leaks.

Colombian banks face a potential indirect cyberattack via an external debt collection provider, compromising customer data such as names, IDs and phone numbers. BBVA and Nu Colombia confirmed the incident and activated security protocols. No entity reports access to keys or deposits.

Сообщено ИИ

Gym chain Sats has confirmed a data breach affecting employees and members after a mid-March cyberattack. Sensitive HR data and member information have surfaced on the darknet, according to IT expert Karl Emil Nikka. The company is still investigating the full scope.

Executives at West Pharmaceutical Services revealed details of a recent cybersecurity breach during a fireside chat at the Bank of America Global Healthcare Conference. The company issued an 8-K filing the previous evening after detecting an intruder in its systems. Officials described shutting down global operations to assess the situation.

Сообщено ИИ

A hacker known as Rootboy has begun daily data dumps from Standard Bank's systems on the dark web since 14 April, following the bank's refusal to pay a 1 Bitcoin ransom. The attack, which started on 27 February, exfiltrated 1.2TB of data from Standard Bank and Liberty. The bank has confirmed exposure of some credit card details but no CVV numbers.

Этот сайт использует куки

Мы используем куки для анализа, чтобы улучшить наш сайт. Прочитайте нашу политику конфиденциальности для дополнительной информации.
Отклонить