Cyber Incident Victim: El Corte Inglés
Date:
Nov 2025
Location:
Spain
Summary
El Corte Inglés experienced a cyberattack after an external provider suffered unauthorized access to its customer databases, exposing personal identifiers, contact details and purchase card numbers of thousands of users. The retailer stated that the compromised data cannot be used to conduct transactions or payments, and that the breach was quickly detected and remedied. It notified relevant authorities and affected individuals, while urging customers to remain calm and confirming that its services remain secure and that it will not request security codes via email or phone. The Organization of Consumers and Users highlighted potential risks such as identity theft, phishing attempts and fraud stemming from the leaked information.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 1, 2025, El Corte Inglés announced that it had suffered a cyberattack that compromised the personal data of thousands of its users. The company stated that the breach originated from an external provider that experienced unauthorized access to its customer databases. According to El Corte Inglés, the incident was detected quickly and the vulnerability was subsequently subsaned. Following detection, the firm notified the relevant authorities and informed the affected users about the compromise. El Corte Inglés acknowledged that cybercriminals had obtained identification and contact information as well as the numbers of its shopping cards. The firm emphasized that, despite the exposure, the compromised data does not enable third parties to carry out transactions or payments with those cards. In an effort to reassure the public, the company issued a call for calm through the Organization of Consumers and Users (OCU). El Corte Inglés also guaranteed that all operations conducted through its services remain completely secure. Furthermore, the retailer declared that it would never contact affected users by email or telephone to request any security code or password.

The OCU outlined the principal risks associated with the data leak, noting that the exposed personal information could be used for identity theft, such as opening bank accounts or applying for loans in the victims' names. The organization warned that attackers might employ the obtained phone numbers or email addresses to conduct phishing campaigns aimed at extracting additional credentials or banking details. It also highlighted that the stolen data could be sold on illicit markets, potentially leading to spam campaigns and other forms of cyber fraud against the affected individuals. El Corte Inglés pointed out that it is not alone in facing such incidents, citing recent cyberattacks on entities including Banco Santander, Ticketmaster, and the Consorcio de Transportes de Madrid. The company maintained that it had taken the necessary steps to address the breach and to protect its users moving forward.
