Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » Dark Web Seller Claims 400,000 German Zalando Customer Records for Sale

Dark Web Seller Claims 400,000 German Zalando Customer Records for Sale

By:
Last updated:September 18, 2026
Human Written
  • A threat actor is offering thousands of customer records belonging to Zalando, a German e-commerce company, for sale.

  • The data includes very sensitive personal info, including names, emails, phone numbers, locations, order data as well as home addresses.

  • No public proof has tied the records to a real Zalando data breach.

Hacker Claims Zalando Data of 400,000 German Customers are for Sale

A forum post claims that someone is selling about 400,000 Zalando customer records online. The post uses the name “Jeffrey Epstein.” The seller says the data comes from German Zalando users and calls it fresh.

The post lists customer IDs, names, email addresses, mobile numbers, cities, regions, countries, and language choices. It also claims to include order counts, last purchase dates, and delivery addresses.

For now, there’s no proof that the data actually came from Zalando or whether the company suffered any data breach recently.

Details of the Zalando Data Breach Claim

The screenshot shows a seller offering 400,000 lines of data linked to Zalando.com. The seller says the records belong to German users. Buyers can ask for a sample and contact the seller on Telegram. The seller also says escrow and middlemen are welcome.

The list covers names, emails, phone numbers, places, and order data. The claimed home address field raises a privacy concern. If real, it could show where some customers live or receive goods.

Still, the post only shows what the seller claims. It does not prove that the seller owns a real Zalando data set. Data sale posts can contain old data or records from another source. Some sellers may also use fake samples. That makes the source and age of the data key questions.

No Proof of a Breach Exposing Zalando Customer Data 

Currently, there’s no real proof that any such breach exposing 400,000 Zalando customer records happened. The only evidence is the forum listing and a threat report. Neither one proves that Zalando lost the data.

There’s no report of a breach of this size on Zalando’s public newsroom yet. Zalando reported 62.5 million active customers as of August 2026. That gives you a sense of just how big its user base is.

According to Zalando’s privacy notice, they do handle all sorts of personal details mentioned in the leak, like account info and delivery data.  The fields could fit the type of data Zalando holds. That does not prove the seller’s sample or claim.

A Separate CEVA Incident Adds Context

The claim comes soon after a cyber incident at CEVA Logistics, which works with Zalando. In August, CEVA reportedly experienced a cyber incident that hit several sites in Europe. Other CEVA clients also reported possible data exposure.

Zalando said two smaller CEVA sites that support its work were affected. The company added that its customer database remains safe. It also took extra measures to secure its systems and moved some of its operations to other sites.

That incident gives the new claim some context. But it does not link the records to CEVA. The CEVA case involved a third-party logistics firm. The forum post makes a separate claim about Zalando customer data.

Other CEVA clients saw different results. ING, for example, said some customer data may have leaked after the CEVA event. That data could include names, addresses, phone numbers, emails and order details. ING said bank data, card data and login details did not form part of the leak. So far, no public source links the Zalando post to the CEVA event.

What the Claimed Data Could Mean

If the claimed data is valid, many customers would be susceptible to all kinds of scams, like phishing and identity theft. Name, address, and phone number can reveal a lot about someone. An order date could make a fake delivery message look real. If scammers get their hands on those, it could make their phishing messages appear legit.

Customer data exposure has affected other online retail platforms as well. In a separate incident, a Pokémon Center data breach exposed UK and German customer information, showing how leaked customer details can create similar privacy and security concerns when attackers obtain personal records.

The same data could help with fake refunds or order problems. A real home address could make such messages more convincing. However, the post does not claim to offer passwords or card numbers.

Customers should not trust a message just because it contains real personal details. Criminals can use old leaks to make messages look real.

What Happens Next

As of the time of reporting, the Zalando breach is still unconfirmed. A lot of things regarding the claim need clarification.

  • Has the seller got access to the data?
  • Are the records part of Zalando’s genuine records?
  • How old are the records?
  • Were the records acquired from Zalando or from any other company?

Zalando itself could resolve some of the issues by analyzing its records. Also, researchers could analyze the sample data to offer further clarification.

This listing appeared on Vercert’s September 17 threat report. There’s still no mention of such a breach in any official statement from Zalando. So, the claim of 400,000 lines of fresh German customer data remains a mere unverified underground market listing until more details surface.

Customers can still take simple steps. Be careful with messages about orders, refunds, or deliveries. Avoid links in unexpected emails and texts. A message can contain your real name or address but still be fake because scammers can buy stolen personal info online just to make their scam convincing. 

Got a message from someone saying they’re from Zalando? Don’t trust the email or text outright; head to Zalando’s official site or open their real app to verify. Don’t bother clicking links or dialing numbers listed in the message itself—they could be total traps.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.