Inditex Reports Unauthorized Access to Internal Databases via Third-Party Breach
Inditex, the Spanish multinational clothing retailer and owner of Zara, confirmed on April 15, 2026, that it suffered a cybersecurity incident involving unauthorized access to its internal databases. The company stated that the breach originated from a security incident affecting a former technology provider, which also impacted other international firms. Inditex emphasized that the compromised databases contained information regarding commercial relationships with clients but explicitly excluded sensitive personal data such as names, addresses, phone numbers, passwords, or payment details. Consequently, the company asserts that no customer personal data was affected. Immediate security protocols were activated, and the incident was reported to the relevant authorities. Inditex assured stakeholders that its core operations and systems remain unaffected, allowing customers to continue transactions securely. The retailer highlighted its robust cybersecurity framework, including an information security committee led by CEO Óscar García Maceiras and a dedicated advisory board. This event underscores the technological risks inherent in highly digitalized business models, though Inditex maintains that normal operational and commercial processes have not been disrupted by this specific incident.
Wire timeline
Inditex Reports Unauthorized Access to Internal Databases via Third-Party Breach
Inditex, the Spanish multinational clothing retailer and owner of Zara, confirmed on April 15, 2026, that it suffered a cybersecurity incident involving unauthorized access to its internal databases. The company stated that the breach originated from a security incident affecting a former technology provider, which also impacted other international firms. Inditex emphasized that the compromised databases contained information regarding commercial relationships with clients but explicitly excluded sensitive personal data such as names, addresses, phone numbers, passwords, or payment details. Consequently, the company asserts that no customer personal data was affected. Immediate security protocols were activated, and the incident was reported to the relevant authorities. Inditex assured stakeholders that its core operations and systems remain unaffected, allowing customers to continue transactions securely. The retailer highlighted its robust cybersecurity framework, including an information security committee led by CEO Óscar García Maceiras and a dedicated advisory board. This event underscores the technological risks inherent in highly digitalized business models, though Inditex maintains that normal operational and commercial processes have not been disrupted by this specific incident.
elpais