- El Corte Inglés notified its customers about unauthorized access to personal data stored by an external provider.
- Customer identification and credit card data were compromised, although the company assures that they cannot be used for fraudulent purchases.
- Additional security measures have been implemented and the incident has been reported to the relevant authorities.
- El Corte Inglés recommends that those affected be alert to possible phishing attempts and change their passwords.

El Corte Inglés has been the victim of a cyberattack that compromised its customers' personal information. The company informed its users about a security breach originating from an external provider, which allowed attackers to access identification and contact data. Although all the details of the incident have not been made public, the company assures that the unauthorized access was detected and resolved immediately.
The incident has generated concern among customers, many of whom have expressed their discontent on social media. The main worry is the possibility that this data could be used in scams such as phishing , where cybercriminals could impersonate El Corte Inglés to obtain more personal information.
What data has been leaked?
According to information provided by El Corte Inglés, the compromised data includes names, surnames, addresses, and credit card numbers linked exclusively to purchases at the company. However, the company has emphasized that this information alone does not allow for fraudulent transactions, so customers can continue using their cards normally.

Despite these statements, many customers have expressed concerns about the nature of the leaked data and the lack of details about the encryption of the information, which opens the door to potential security risks.
Response from El Corte Inglés and measures taken
El Corte Inglés has confirmed that, upon detecting the intrusion, security protocols were immediately activated to mitigate the impact of the attack. Furthermore, they have requested that the affected provider implement additional measures to prevent future incidents.
The company has also notified the relevant data protection authorities so that they can carry out the necessary investigations and ensure compliance with security regulations.
As part of its response to protect customers, the company has also emphasized that it will never ask for passwords, security codes or sensitive information via email, phone call or text message.
Recommendations for affected customers
Given this situation, El Corte Inglés has recommended that its customers change their website access passwords and remain vigilant against possible identity theft attempts.
Those who suspect they have received fraudulent emails should avoid clicking on suspicious links and contact El Corte Inglés customer service directly to verify any official communication.

Additionally, it is recommended that you do not share personal information with third parties and activate extra security measures such as two-step authentication on services that offer it. For more information on how to protect your data, you can consult our guide on how cybersecurity works.
Customer outrage and lack of transparency
The fact that El Corte Inglés has sent communications to its customers at unusual times and with a generic subject has generated criticism. Many users point out that this strategy seems designed to minimise the media impact and avoid a major repercussion.
Another aspect that has raised questions is the decision not to reveal the name of the affected provider or to offer technical details about whether the data was encrypted. This lack of transparency has been questioned, as other similar incidents have shown that data encryption can be key to minimising damage.
Some customers have expressed their distrust on social media and demanded more information about what happened. The controversy has reignited the debate about digital security and the responsibility of large companies to protect their users' data.

The attack on El Corte Inglés adds to a long list of security breaches suffered by companies in various sectors in recent years. The leakage of personal data is a growing problem that affects both customers and companies, highlighting the need to strengthen cybersecurity protocols.
Although the company has stated that it has strengthened security measures to prevent similar incidents in the future, the confidence of many customers may have been affected. The general recommendation remains to exercise caution against potential fraud attempts and to be vigilant for any suspicious communications.