ManoMano
Incident posture
Timeline
Summary
ManoMano experienced a data breach when hackers compromised a customer service subcontractor based in Tunisia, gaining access to its support portal and exfiltrating personal information including names, email addresses, phone numbers, and customer service exchanges. The threat actor known as Indra claimed on BreachForums to have stolen approximately 43 gigabytes of data, encompassing details from about 37.8 million user accounts, over 900,000 service tickets, and more than 13,000 attachments affecting users across the company's operations in France, Germany, Italy, Spain, and the United Kingdom.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In January 2026, attackers gained access to ManoMano’s support portal after compromising a customer service subcontractor based in Tunisia. The breach was discovered and disclosed by ManoMano in the week of February 27, 2026, when the company began notifying potentially affected customers. According to the notification shared on X, the stolen data included customers’ names, email addresses, phone numbers, and the contents of customer service exchanges. A threat actor using the alias ‘Indra’ claimed responsibility for the intrusion on the underground forum BreachForums. Indra asserted that approximately 43 gigabytes of data were exfiltrated from ManoMano’s systems. The claimed haul comprised information linked to about 37.8 million ManoMano user accounts, over 900,000 service tickets, and more than 13,000 attached files.
The compromised data reportedly concerns ManoMano users in all five European countries where the retailer operates, namely France, Germany, Italy, Spain, and the United Kingdom. SecurityWeek reported that roughly 38 million individuals were likely impacted by the incident. ManoMano began notifying potentially affected customers after the breach was disclosed. SecurityWeek contacted ManoMano for a statement regarding the attacker’s claims and indicated it would update its coverage if the company responded.
Sources
Sources available to members: 1 source.