Inditex suffers a cyber attack with access to internal databases

Inditex suffers a cyber attack with access to internal databases

Inditex announced on Wednesday night that it had suffered unauthorized access to the company’s databases, which were hosted on servers of a third-party provider.

Read more National Lottery and Panini allude to nostalgia in a retro Mexican football album

The Galician textile group says that these databases “contain information about the commercial relationship with customers from different markets, but in no case data such as first and last names, phone numbers, addresses, passwords, bank cards or other means of payment,” so, in principle, it rules out that personal data of customers have been affected.

The company that owns Zara explains that it has reported the incident to the “relevant authorities,” after having “immediately” applied its security protocols. The security breach, it adds, “originates from an incident suffered by a former technology provider that has affected various companies with international operations.” “Inditex’s operations and systems have not been affected in any way and customers can continue to access and operate with complete security,” the company says in a statement shared with the media.

As is usual in this type of multinational, Inditex identifies cybersecurity as one of the elements of its risk map. “Given the high degree of digitization and technological integration of the business model, the possible materialization of technological incidents — derived, among other factors, from infrastructure failures, cybersecurity incidents, application errors or difficulties in interaction with third-party technology providers — could have a cross-cutting impact on the group’s activity, affecting the normal development of operational and commercial processes,” it says in its latest annual report. This last point, according to the company’s explanation, has not happened.

Inditex has an information security committee dedicated to the “mitigation of technological and cybersecurity risks,” as well as to the “protection of the group’s critical information,” and which includes, among other senior executives, the CEO, Óscar García Maceiras.

Additionally, in 2023 it established a cybersecurity advisory committee, which serves as a consultative body to the board of directors on information security matters. For example, this body met five times in 2025, during which “the risks of the geopolitical context, the impact of artificial intelligence, the most common threats and new intrusion techniques were reviewed, highlighting the need to strengthen internal training and awareness,” as described in the group’s annual report.

Read more The best Madrid shows up in the Champions farewell

The same report explains the different teams it has in this area: one specialized in cyber intelligence; or a security operations center operating 24 hours a day, “responsible for detecting, analyzing, reporting and resolving potential security events that may affect the company.” During 2025, it identified 66 events of interest that were reported to the security committee, without notable impacts.

This is not the first case of a Spanish retail company suffering a cyberattack with access to databases.

In October, Mango reported having suffered unauthorized access to certain personal customer data through an external marketing service. Cybercriminals were able to obtain personal data used in marketing campaigns; first names without last names, country of origin, postal codes, phone numbers, and email addresses.

Another major company in the sector, El Corte Inglés, suffered a cyberattack last March that allowed cybercriminals to access personal data of the distribution group’s customers, which were also hosted by an external provider.

Read more And what is the alternative to the 4T?

Translated from

Leave a Reply

Your email address will not be published. Required fields are marked *