CSIDB logo
Incident

El Corte Inglés

Incident posture

Attack window
Nov 2025
Location
Spain
Status
Resolved
CIA posture
Available to members
Updated
2026-08-17 17:12

Linked entities

Victim
El Corte Inglés
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Mar 2025
Resolved
Undetermined

Summary

El Corte Inglés experienced a cyberattack that exposed personal data of thousands of customers after an external provider suffered unauthorized access to its databases. The compromised information includes names, contact details and the company's shopping card numbers, though it states the data cannot be used to conduct transactions or payments. Authorities and affected users were notified, and the firm emphasized it will not contact individuals to request security codes or passwords. The breach raises risks of identity theft, phishing attempts and fraud, as the data could be sold or used for further attacks.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 1, 2025, El Corte Inglés reported that it had suffered a cyberattack affecting the personal data of most of its users. The company stated that the breach originated from an external provider that experienced unauthorized access to its customer databases. Although the incident was detected quickly and the company said it had been remedied, the leakage of data had already occurred. Cybercriminals obtained identification and contact information of customers as well as the numbers of El Corte Inglés shopping cards.

El Corte Inglés notified all relevant authorities and the affected individuals about the breach. The retailer issued a call for calm through its customer service, guaranteeing that all transactions remain secure. It also clarified that it would never contact affected users by email or telephone to request any security code or password. The Organization of Consumers and Users (OCU) echoed the call for calm and outlined the potential risks associated with the exposed data.

The OCU warned that the compromised data could be used for identity theft, such as opening bank accounts or applying for loans in victims' names. It also noted that phone numbers and email addresses could be leveraged for phishing attempts to harvest additional credentials or banking information. Furthermore, the data could be sold on illegal markets, leading to spam campaigns and other cyber attacks. El Corte Inglés added that the incident places it among other Spanish entities, including Banco Santander, Ticketmaster, and the Consorcio de Transportes de Madrid, that have faced similar cyberattacks in recent months.

Sources

Sources available to members: 1 source.

CSIDB