Zara Data Breach Exposes 197,000 Records via Anodot Incident
Fashion retailer Zara, a flagship brand of the Inditex Group, confirmed that approximately 197,400 customer records were exposed in a significant data breach. The incident is linked to a broader cyberattack on Anodot, an AI-powered cloud analytics platform, by the ransomware group ShinyHunters. The attackers leaked 140GB of data from Zara’s BigQuery instances, which included email addresses, purchase histories, and support tickets. Despite the scale of the leak, Inditex stated that highly sensitive personal information, such as names, physical addresses, login credentials, and payment details, was not accessed or stolen. This distinction significantly reduces the immediate financial risk to affected customers. However, security experts warn that the combination of exposed emails and specific purchase details could facilitate sophisticated, tailored phishing campaigns targeting Zara shoppers. This breach highlights the cascading risks associated with third-party service integrations, as ShinyHunters exploited vulnerabilities in Anodot to access data from multiple companies connected to the platform. The event underscores the ongoing challenges in securing cloud-based supply chains and the persistent threat posed by organized cybercriminal groups targeting large retail ecosystems.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection