El Corte Inglés
Incident posture
Linked entities
- Victim
- El Corte Inglés
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
El Corte Inglés experienced a cyberattack that exposed personal data of thousands of customers after an external provider suffered unauthorized access to its databases. The compromised information includes names, contact details and the company's shopping card numbers, though it states the data cannot be used to conduct transactions or payments. Authorities and affected users were notified, and the firm emphasized it will not contact individuals to request security codes or passwords. The breach raises risks of identity theft, phishing attempts and fraud, as the data could be sold or used for further attacks.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On March 1, 2025, El Corte Inglés reported that it had suffered a cyberattack affecting the personal data of most of its users. The company stated that the breach originated from an external provider that experienced unauthorized access to its customer databases. Although the incident was detected quickly and the company said it had been remedied, the leakage of data had already occurred. Cybercriminals obtained identification and contact information of customers as well as the numbers of El Corte Inglés shopping cards.
El Corte Inglés notified all relevant authorities and the affected individuals about the breach. The retailer issued a call for calm through its customer service, guaranteeing that all transactions remain secure. It also clarified that it would never contact affected users by email or telephone to request any security code or password. The Organization of Consumers and Users (OCU) echoed the call for calm and outlined the potential risks associated with the exposed data.
The OCU warned that the compromised data could be used for identity theft, such as opening bank accounts or applying for loans in victims' names. It also noted that phone numbers and email addresses could be leveraged for phishing attempts to harvest additional credentials or banking information. Furthermore, the data could be sold on illegal markets, leading to spam campaigns and other cyber attacks. El Corte Inglés added that the incident places it among other Spanish entities, including Banco Santander, Ticketmaster, and the Consorcio de Transportes de Madrid, that have faced similar cyberattacks in recent months.
Sources
Sources available to members: 1 source.