Skip to main content
Back to overview
High

Zara (Inditex) Data Breach by ShinyHunters Exposes 197,000 Customer Records via Third-Party Vendor

On May 8, 2026, Zara, a brand of the Spanish fashion giant Inditex, confirmed a data breach that exposed personal information of approximately 197,000 customers.

Key points

  • Attributed to the ShinyHunters extortion group.
  • Exploited compromised authentication tokens of a former third-party analytics provider, Anodot.
  • Exposed approximately 197,000 unique customer email addresses.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Partner actor · Confidentiality impact

Possible third-party involvement

03

Potential impact

Data Exposure

Confidentiality

Published
May 8, 2026
Updated
Jul 3, 2026
Confidence
High
Evidence
8 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Possible third-party involvement

Watch exposure paths that could affect data, operations or third-party trust.

  • Source type: supplier or third-party involvement

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

ZaraData DisclosureZaraInditexShinyHunters ExposesThird-Party Vendor On MaySpanishShinyHuntersAnodotExposed

Quick context

Questions about this signal

What happened in this signal?

On May 8, 2026, Zara, a brand of the Spanish fashion giant Inditex, confirmed a data breach that exposed personal information of approximately 197,000 customers. The incident was attributed to the ShinyHunters extortion group, which exploited compromised authentication tokens of a former third-party analytics provider, Anodot, to access customer data. Exposed data included email addresses, geographic locations, purchase history, and support tickets, though Inditex stated that names, passwords, addresses, and payment information were not compromised.

When was this signal reported?

Shadow Tier lists May 8, 2026 as the signal date.

Which organization is connected to this signal?

Zara is the organization connected to this public signal.

Explore Zara
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence