A new cybersecurity incident has been added to the long list of attacks targeting the retail and fashion, with Zara taking center stage this time. According to data leak Have I Been Pwned, hackers managed to gain access to databases related to the Spanish fast fashion chain and extract data related to more than 197,000 customers.
The incident affects one of the world's most recognizable clothing companies, as Zara is a core brand of the Inditex, which manages thousands of physical stores internationally and also includes well-known names such as Bershka, Pull&Bear, Massimo Dutti and Stradivarius.
The attack chain and the role of third-party providers
According to Inditex, the incident was not due to a direct breach of the company's central systems, but to the infrastructure of a former technology service provider. The compromised databases contained information mainly related to business transactions and customer support in different markets.
See also: Canvas breach affects schools and universities in the US

The company emphasizes that no sensitive personal data such as names, payment details, passwords or addresses were exposed, while it assures that its operating systems were not affected. At the same time, it immediately initiated procedures to notify the competent authorities and activated its security protocols.
The ShinyHunters involvement and the leak of 140GB of data
The case gained more traction when the well-known cybercrime group ShinyHunters claimed responsibility for the attack, claiming to have gained access to a huge amount of data. According to the information, the group leaked a file of approximately 140GB, which included data allegedly coming from cloud infrastructures such as BigQuery, using compromised authentication tokens.
Have I Been Pwned's analysis showed that the data included 197,000 unique email addresses , order information, product identifiers (SKUs), geographic locations, and customer support requests , giving the attackers a fairly detailed picture of consumer activity.

An extensive network of cyberattacks
ShinyHunters are no strangers to cybersecurity. In recent months, they have been linked to a series of attacks on major technology, entertainment, and retail companies, using a combination of techniques such as vishing, SSO system compromise , and cloud infrastructure exploitation.
See also: Ollama vulnerability allows sensitive information to be leaked
The group has targeted corporate accounts on platforms such as Microsoft Entra, Okta, and Google SSO, gaining access to connected SaaS services such as Salesforce, Slack, Google Workspace, and Microsoft 365. These types of attacks allow for indirect penetration of multiple corporate systems through a single point of breach.
A recurring pattern of attacks on the fashion industry
Zara's incident is not an isolated one. In October, Spanish retailer MANGO announced personal data customers' through a third-party marketing provider, while recently there has been an increase in cyberattack activity on retail companies worldwide.
This trend shows that attackers are no longer just targeting businesses themselves, but also their entire ecosystem of partners, looking for weak points in the data supply chain.

The broader problem of data security in the cloud
The case highlights once again the importance of security in cloud infrastructures and third-party service providers. Even if the core corporate infrastructure remains secure, reliance on external systems creates additional points of risk.
See also: Braintrust confirms breach – Need to change API keys
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Experts point out that such incidents reinforce the need for stricter access control, stronger encryption , and constant monitoring of partners in companies' digital ecosystem.
In an environment where attacks are becoming increasingly targeted and sophisticated, data protection is no longer just a technical issue, but a critical trust factor for millions of consumers worldwide.
Source: www.bleepingcomputer.com
