ManoMano Data Breach Affects 38 Million Users Globally
ManoMano Data Breach Impacts 38 Million Customers
A recent data breach at European DIY retailer ManoMano has potentially impacted 38 million customers, after hackers compromised a customer support portal in January. The incident was disclosed this week, with the company notifying affected customers and providing details on the stolen data.
Details of the Breach
According to ManoMano, the breach occurred when a customer service subcontractor was compromised, allowing hackers to access sensitive customer information. The stolen data includes names, addresses, phone numbers, and customer service exchanges. The company has not disclosed the specific platform used for customer support, but it appears that the hackers accessed ManoMano’s Zendesk instance.
A threat actor claiming responsibility for the breach, using the name “Indra,” posted on the underground hacking forum BreachForums, stating that they stole approximately 43GB of data from the company. The stolen data allegedly includes information associated with 37.8 million ManoMano user accounts, over 900,000 service tickets, and over 13,000 attachments. The data pertains to ManoMano users across five European countries, including France, Germany, Italy, Spain, and the United Kingdom.
Investigation and Response
The hacker claimed to have accessed the company’s data after compromising a customer support service provider in Tunisia. ManoMano has not confirmed the specifics of the attack, but the company has notified affected customers and is likely conducting an investigation into the incident.
About ManoMano
ManoMano, a French company, operates a popular DIY, gardening, and home improvement e-commerce website, with over 50 million visitors per month. The company has not disclosed any information on the financial impact of the breach or any potential consequences for affected customers.
Security Implications
The breach highlights the importance of securing customer support platforms and subcontractor relationships, as these can provide a vulnerable entry point for hackers. Companies must prioritize the security of sensitive customer data and ensure that all third-party providers adhere to robust security standards.
