European DYI chain ManoMano data breach impacts 38 million customers
嗯,用户让我用中文总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要仔细阅读文章内容,抓住主要信息。 文章讲的是ManoMano,一个法国的DIY连锁店,遭遇了数据泄露。黑客入侵了他们的第三方客服提供商。事件发生在2026年1月,影响了3800万人。泄露的信息包括姓名、邮箱、电话和客服交流记录,但没有密码被泄露。公司已经通知了客户,并采取措施加强安全。 接下来,我需要把这些要点浓缩到100字以内。要确保涵盖事件的时间、影响人数、泄露的数据类型、公司的应对措施以及第三方的责任。 可能的结构是:时间+公司名称+数据泄露原因+影响人数+泄露信息+应对措施。这样既简洁又全面。 检查一下有没有遗漏的重要信息,比如第三方是客服提供商,这一点很重要,说明不是直接攻击公司系统。还有提到没有密码泄露和数据修改,这也是关键点。 最后,确保语言简洁明了,不使用复杂的句子结构。 </think> 法国DIY电商平台ManoMano因第三方客服提供商遭黑客入侵,导致3800万人个人信息泄露。泄露数据包括姓名、邮箱、电话及客服交流记录,未涉及密码或数据篡改。公司已通知受影响用户并采取安全措施。 2026-2-26 17:45:57 Author: www.bleepingcomputer.com(查看原文) 阅读量:0 收藏

European DYI chain ManoMano data breach impacts 38 million customers

DIY store chain ManoMano is notifying customers of a data breach that was caused by hackers compromising a third-party service provider.

The company confirmed to BleepingComputer that it learned of the hack in January 2026. An investigation into the incident determined that 38 million individuals are affected.

“We can confirm that ManoMano has recently notified customers about a security incident involving one of our third-party customer service providers (a subcontractor),” the company told BleepingComputer.

Wiz

“In January 2026, we identified unauthorized access linked to this provider, which resulted in the unauthorized extraction of certain personal data associated with customer accounts and customer service interactions.”

ManoMano is a French e-commerce firm operating an online marketplace specializing in DIY, home improvement, gardening, and related products. It operates in France, Belgium, Spain, Italy, Germany, and the United Kingdom, and its e-stores reportedly have 50 million unique visitors per month.

Earlier this month, someone using the alias “Indra” claimed the ManoMano attack on a hacker forum, alleging that they were holding details on 37.8 million user accounts, as well as thousands of support tickets and attachments.

According to unconfirmed reports, the compromised organization was a Tunis-based customer support service provider that suffered a Zendesk breach.

Cybersecurity firm Hackmanac posted that ManoMano started notifying customers this week that their data had been stolen.

A spokesperson of ManoMano explained to BleepingComputer that the exposed information varies per individual, depending on the type of interactions they had with the platform. Exposed data types include:

  • Full name
  • Email address
  • Phone number
  • Customer service communications

ManoMano emphasizes that no account passwords were accessed and that no data modifications occurred on the company’s systems.

“Upon discovery, we took immediate steps to secure our environment, including disabling the relevant access, revoking the subcontractor’s access to customer data, and strengthening access controls and monitoring,” said a ManoMano spokesperson.

“We also notified the relevant authorities, including the CNIL and ANSSI, and informed impacted customers with guidance to remain vigilant against phishing and social engineering attempts.”

Notice sent to customers
Notice sent to customers
Source: ManoMano

The notification sample ManoMano shared with BleepingComputer contains recommendations for customers, including verifying incoming communications and sender identity, monitoring bank accounts for fraudulent transactions, and avoiding clicking on suspicious links or downloading email attachments.

ManoMano notes that the investigation is ongoing and that they cannot share additional technical details at this stage.

tines

The future of IT infrastructure is here

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.


文章来源: https://www.bleepingcomputer.com/news/security/european-dyi-chain-manomano-data-breach-impacts-38-million-customers/
如有侵权请联系:admin#unsafe.sh