ManoMano data breach impacted 38 Million customer accounts
好的,我现在需要帮用户总结一篇文章,控制在100字以内。用户给了一篇关于ManoMano数据泄露的报道。首先,我要快速浏览文章内容,抓住主要信息。 文章提到,ManoMano是一个欧洲DIY电商平台,在2026年1月遭受了数据泄露,影响了3800万用户。泄露的原因是第三方服务提供商被入侵,导致用户的个人信息如姓名、邮箱、电话号码等被泄露。幸运的是,密码没有被泄露。公司已经采取措施封锁账户,并通知了相关机构。 接下来,我需要将这些信息浓缩到100字以内。要注意时间、受影响人数、原因、泄露的数据类型以及公司的应对措施。同时,语言要简洁明了,避免使用复杂的词汇。 可能的结构是:平台名称+事件时间+受影响人数+原因+泄露数据+应对措施。这样既全面又简洁。 现在开始组织句子:欧洲DIY平台ManoMano于2026年1月因第三方服务提供商被入侵,导致3800万用户的数据泄露,包括姓名、邮箱和电话号码等信息。公司已封锁账户并通知相关机构。 检查字数是否在限制内,并确保没有遗漏关键点。看起来符合要求。 </think> 欧洲DIY平台ManoMano于2026年1月因第三方服务提供商被入侵,导致3800万用户的数据泄露,包括姓名、邮箱和电话号码等信息。公司已封锁账户并通知相关机构。 2026-2-27 07:41:50 Author: securityaffairs.com(查看原文) 阅读量:4 收藏

ManoMano data breach impacted 38 Million customer accounts

Pierluigi Paganini February 27, 2026

European DIY platform ManoMano suffered a data breach via a third-party provider, exposing personal data of 38 million customers.

European DIY e-commerce platform ManoMano disclosed a major data breach affecting 38 million customers. Hackers accessed personal information by compromising a third-party service provider, prompting notifications and potential security measures for impacted users across multiple countries.

ManoMano is a European e-commerce platform specializing in DIY, home improvement, gardening, and tools. Founded in 2013, it connects consumers with a wide range of products—from power tools and plumbing supplies to outdoor furniture and gardening equipment—offered by multiple sellers, including brands and independent retailers.

ManoMano confirmed to BleepingComputer that it discovered a security breach in January 2026 affecting 38 million customers. The incident involved a third-party service provider, whose unauthorized access led to the extraction of personal data linked to customer accounts and service interactions. The company has notified affected users and is investigating the scope of the compromise.

“In January 2026, we identified unauthorized access linked to this provider, which resulted in the unauthorized extraction of certain personal data associated with customer accounts and customer service interactions.” the company told BleepingComputer.

According to the data breach notification sent to the impacted customers, the exposed data includes: first name, last name, email address, telephone number, and your eventual interactions with our customer service.

The company pointed out that user passwords were not compromised.

Upon detecting the breach, the company immediately blocked the compromised account and revoked the subcontractor’s access. Enhanced data access controls were implemented internally and for all subcontractors. Authorities, including CNIL, ANSSI, and the Cyber Emergency Île-de-France platform, were informed to ensure proper oversight and response.

“As soon as the incident was identified, we immediately took all necessary measures to protect your data.

The analyses conducted by our cyber security teams allowed for the quick identification of the compromised account, which was blocked on the same day the incident was discovered. Subsequently, we revoked all of our subcontractor’s access to our customers’ data.” reads the data breach notification sent to the impacted users.

“We have also implemented reinforced controls on data access, both within our company and at our other subcontractors. Finally, we informed the CNIL (French National Commission for Information Technology and Civil Liberties), the ANSSI (French National Agency for the Security of Information Systems) and the Cyber Emergency Île-de-France platform.”

#ManoMano
Gentile Cliente,
siamo stati recentemente informati che uno dei nostri fornitori di servizi clienti (subappaltatore) è stato vittima di un attacco informatico nel gennaio 2026, che ha comportato un download non autorizzato di dati personali pic.twitter.com/UYvRxoPz3r

— JAMESWT (@JAMESWT_WT) February 12, 2026

In February, a threat actor using the alias “Indra” claimed responsibility for the data breach, allegedly holding data on 37.8 million users, including support tickets.

The investigation into the incident is still ongoing.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, data breach)




文章来源: https://securityaffairs.com/188582/data-breach/manomano-data-breach-impacted-38-million-customer-accounts.html
如有侵权请联系:admin#unsafe.sh