Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

38 Million Allegedly Impacted by ManoMano Data Breach

Hackers stole personal information such as names, email addresses, phone numbers, and other information.

ManoMano data breach

Roughly 38 million people were likely impacted by a data breach at European DIY store chain ManoMano after hackers compromised a support portal.

The attack occurred in January and was disclosed this week, when ManoMano started notifying the potentially affected customers of the incident.

According to the company’s notification, copies of which were shared on X, the data was stolen after a customer service subcontractor was compromised.

The hackers stole customers’ names, email addresses, and phone numbers, along with customer service exchanges.

While ManoMano has not shared details on the hacked platform, it appears that the hackers accessed its Zendesk instance, used by the company for customer support.

A threat actor using the name of ‘Indra’ claimed the attack on the underground hacking portal BreachForums, saying they stole roughly 43GB of data from the company.

Advertisement. Scroll to continue reading.

The data, the threat actor claims, includes information associated with 37.8 million ManoMano user accounts, over 900,000 service tickets, and over 13,000 attachments.

The stolen data allegedly pertains to ManoMano users across all five European countries where it operates, namely France, Germany, Italy, Spain, and the United Kingdom.

The hacker allegedly accessed the company’s data after compromising a customer support service provider in Tunisia.

SecurityWeek has emailed ManoMano for a statement on the attacker’s claims and will update this article if the company responds.

A French company, ManoMano owns a popular DIY, gardening, and home improvement ecommerce website that has over 50 million visitors per month.

Related: CarGurus Data Breach Impacts Over 12 Million Users

Related: Wynn Resorts Confirms Data Breach After Hackers Remove It From Leak Site

Related: US Healthcare Diagnostic Firm Says 140,000 Affected by Data Breach

Related: PayPal Data Breach Led to Fraudulent Transactions

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Jonathan Trull has joined Oracle as Global Head of Cyber Defense.

Plaid has appointed Sean Cassidy as Chief Information Security Officer.

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.