Menu
Browse

El Corte Inglés

Primary URL Location Industry
www[.]elcorteingles[.]es
Country Spain
Retail Icon
Retail
Profile

El Corte Inglés, also known by its alias, is a retailer headquartered in Spain. The company operates as a commercial entity that serves customers through its retail activities. While the specific product range is not detailed in the source material, its role as a retailer is confirmed by its public statements regarding customer data. The organization’s primary market is Spain, where its headquarters is located. No further details about subsidiaries, ownership structure or international footprint are provided in the available information.

On 1 November 2025, El Corte Inglés experienced a cyberattack that originated from unauthorized access to an external provider’s customer databases. The breach exposed personal identifiers, contact details and purchase card numbers of thousands of users. The retailer stated that the compromised data could not be used to conduct transactions or payments and that the incident was quickly detected and remedied. It notified the relevant authorities and the affected individuals, while urging customers to remain calm and confirming that its services remain secure. The company also clarified that it would never request security codes via email or phone, and the Organization of Consumers and Users warned of possible identity theft, phishing and fraud stemming from the leaked information.

A earlier incident occurred on 1 March 2025, when El Corte Inglés suffered a similar cyberattack after an external provider gained unauthorized access to its customer databases. Personal identification, contact details and purchase card numbers of thousands of users were exposed in this breach as well. The company stated that the compromised data did not allow third parties to perform transactions or payments with the cards and emphasized that the breach was quickly detected and remedied. It notified authorities and affected individuals, assured that its services remained secure, and clarified that it would never contact users by email or phone to request security codes or passwords. The second event was noted as adding to a series of recent data leaks affecting other major organizations, highlighting ongoing risks such as identity theft, phishing and fraud.

Incidents
Linked incidents available to members
2 incidents