The Zara breach again shows that third-party and former-provider environments remain a serious blind spot. Even when core systems, credentials, payment data, and operations are reportedly unaffected, exposed emails, purchase details, order IDs, support tickets, and geographic information are still valuable for phishing, impersonation, and targeted scams. Attackers do not need card numbers when they already have enough context to make a fake support or refund message look believable.

Consumers should be cautious of emails or messages claiming to be from Zara, Inditex, delivery partners, or customer support, especially those asking them to verify orders, claim refunds, update payment details, or log in through links. For businesses, this is another reminder that vendor offboarding, SaaS token governance, data retention, and access reviews must be treated as active security controls, not paperwork for auditors to admire before everyone forgets it exists. The report says Have I Been Pwned identified data for about 197,400 people, including email addresses, locations, purchases, order IDs, SKUs, and support-ticket market details


Hackers who gained access to the databases of Spanish fast-fashion retailer Zara stole data belonging to more than 197,000 customers, according to data breach notification service Have I Been Pwned. [...]

Source: Zara data breach exposed personal information of 197,000 people via Bleeping Computer — published 08 May 2026.