Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Data Breaches

Major Spanish Retail Brand Hacendado Allegedly Breached, 27 Million Users’ Data Offered for Sale

June 4, 2025
Reading Time: 1 min read
Major Spanish Retail Brand Hacendado Allegedly Breached, 27 Million Users’ Data Offered for Sale

Hacendado, a prominent Spanish brand primarily associated with Mercadona, one of Spain’s largest supermarket chains, has allegedly fallen victim to a significant data breach. An unauthorized actor claims to have exploited a zero-day vulnerability within a third-party logistics and inventory management system integrated with Hacendado’s backend infrastructure, leading to the compromise of extensive user data. Hacendado is a widely recognized private label for Mercadona, offering a vast range of grocery and household products, making Mercadona a key player in the Spanish retail sector with millions of customers across Spain and Portugal. The scale of its operations means a data breach could have widespread consequences for its customer base.

The perpetrator of the alleged breach is offering a substantial dataset for private sale, reportedly containing information on over 27 million unique users. The compromised data is described as raw and unfiltered, directly scraped from the affected systems. The actor also claims to possess exclusive rights to the unpatched zero-day vulnerability, indicating it has not been reported or fixed. The origin of the breach is attributed to this previously unknown flaw in a third-party vendor’s software, highlighting the persistent risks associated with supply chain vulnerabilities.

The following data categories are allegedly included in the breach:

  • Full names, emails, and hashed passwords
  • Location data and purchase history
  • Internal employee emails and operational logs
  • Fragmented payment metadata
  • Tokens and access credentials (partially obfuscated)
Tags: alleged breachCyberSecuritydata-breachHacendadoMercadonaRetailSpainthird-party vendoruser dataZero-Day
ShareTweet

Related Posts

Uganda Ministry of Agriculture MAAIF Suffers Data Breach
Data Breaches

Uganda Ministry of Agriculture MAAIF Suffers Data Breach

April 27, 2026
Ellipal Cryptocurrency Wallet Suffers Alleged Data Breach
Data Breaches

Ellipal Cryptocurrency Wallet Suffers Alleged Data Breach

April 27, 2026
BlackSexFinder Adult Platform Suffers Massive Data Breach
Data Breaches

BlackSexFinder Adult Platform Suffers Massive Data Breach

April 27, 2026
Jeff Honeycutt Insurance Agency Data Breach Exposes Client Info
Data Breaches

Jeff Honeycutt Insurance Agency Data Breach Exposes Client Info

April 27, 2026
FFWPU and Tongil Group Face Extensive Data Breach
Data Breaches

FFWPU and Tongil Group Face Extensive Data Breach

April 27, 2026
Terra West Management Services Suffers Major Data Breach
Data Breaches

Terra West Management Services Suffers Major Data Breach

April 24, 2026
Next Post
Nepal Police Allegedly Breached, Sensitive Data Appears for Sale Online

Nepal Police Allegedly Breached, Sensitive Data Appears for Sale Online

Odoo Employee Database Allegedly Leaked by Insider, For Sale on Dark Web

Odoo Employee Database Allegedly Leaked by Insider, For Sale on Dark Web

Recommended Stories

Alleged EduSports Breach Leaked 70K Rows

Alleged EduSports Breach Leaked 70K Rows

August 15, 2024
Qilin Ransomware Allegedly Breaches French Wholesaler Wouters France

Qilin Ransomware Allegedly Breaches French Wholesaler Wouters France

September 10, 2025
LulzSec Black and Moroccan Soldiers Launch Major Attacks on Turkish Infrastructure

LulzSec Black and Moroccan Soldiers Launch Major Attacks on Turkish Infrastructure

July 8, 2024

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?