DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
Cybersecurity

ManoMano Says About 38 Million People Were Affected by a Third-Party Data Breach

ManoMano says a third-party customer-service breach affected about 38 million people. Here is what is confirmed, what remains alleged and how customers should respond.

By TheFinanceBase Team 6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ManoMano said approximately 38 million individuals were affected by unauthorized access discovered in January 2026 at a third-party customer-service provider. The company said exposed information could include names, email addresses, telephone numbers and customer-service communications. It also said account passwords were not accessed and that no data was modified in its systems.

Those are company statements, not a completed independent forensic account. A threat actor using the name “Indra” reportedly claimed data from about 37.8 million accounts, while reports cited claims of 43 GB of data, nearly one million support tickets and about 13,000 attachments. Customers should treat the incident primarily as a phishing and impersonation risk, while securing any reused credentials.

What happened in the ManoMano breach?

ManoMano said it identified unauthorized access in January 2026 involving a third-party customer-service provider. The company subsequently disabled the provider’s access, increased monitoring and said it notified customers, the French data-protection authority CNIL and France’s cybersecurity agency ANSSI. BleepingComputer reported the company’s account on February 26, 2026: ManoMano data breach impacts 38 million customers.

The available public information describes a vendor-related incident rather than a confirmed compromise of ManoMano’s core shopping platform. Reports have linked the provider’s support environment to Zendesk, but ManoMano has not published a complete technical account identifying the subcontractor, proving that Zendesk itself was breached or explaining the initial-access method.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How large was the alleged exposure?

“38 million” is ManoMano’s reported estimate of affected individuals. It is not an independently verified count of unique customers, accounts or records. The number may not match the data claimed by the attacker.

Figure or description What is established
Approximately 38 million individuals ManoMano’s estimate of people affected, according to the company.
Approximately 37.8 million accounts Reportedly claimed by the threat actor “Indra”; not independently verified.
About 43 GB of data Attributed in reporting to attacker claims or third-party analysis, not a complete public forensic report.
Nearly 900,000 to one million support tickets Reported or attacker-derived estimate; the exact total is not established.
About 13,000 attachments Reported or attacker-derived estimate; exposure of any particular customer’s file is not established.

The company’s person estimate and the alleged account dataset should therefore not be presented as the same measurement. As of August 18, 2026, no public final forensic report established the exact number of unique people, the complete contents of the dataset or which records belonged to which customer.

What information may have been exposed?

Categories ManoMano identified

ManoMano said the affected information varied by person and could include:

  • Full name
  • Email address
  • Telephone number
  • Customer-service communications

Support conversations can contain order or delivery context, refund discussions, product problems and details a customer voluntarily supplied. That context can make a fake refund, delivery or account-verification message sound credible.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Additional material reported by third parties

Security reporting and the alleged attacker’s posts have referred to support tickets, attachments and a large exported dataset. Those descriptions remain claims or estimates. They do not show that every ticket or attachment was exposed, nor that every affected person had a support case.

Were passwords or payment details stolen?

ManoMano said account passwords were not accessed and that no data was modified in its systems. Those statements should be attributed to the company; the public record does not contain a completed independent audit confirming every boundary of the provider environment.

Available reporting does not establish exposure of payment-card numbers, bank credentials, government identification numbers, authentication tokens or the complete order history of any customer. “Not reported” is not the same as an independent proof that financial information could not have existed anywhere in the vendor environment. Follow your individual notification if it identifies more specific data.

Which countries and customers are affected?

ManoMano operates across France, Belgium, Spain, Italy, Germany and the United Kingdom, and the incident appears centered on those European operations. The company’s reported total is not broken down publicly by country in the information available here.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Having an account but never contacting support does not prove that you were unaffected. Conversely, contacting support does not prove that your ticket or attachment was included. The only reliable confirmation for an individual is a genuine notice from ManoMano or a response through its official support channels.

Readers in the United States should not assume that European notification rules, regulator actions or legal remedies apply in the same way to them. The available reporting does not establish a separate U.S. incident or a U.S.-specific compensation program.

Why phishing is the main near-term risk

Names, contact details and support history can enable targeted phishing, phone scams and text-message impersonation. An attacker who knows that a customer disputed a delivery or requested a refund can create a more convincing message than a generic spammer. This is a risk assessment based on the reported data categories, not evidence that every customer has already been targeted or suffered fraud.

Do not infer from the absence of reported password theft that the incident is harmless. Stolen context can be used to harvest credentials for other services, redirect refunds, persuade a victim to disclose a card number or attack the email account used for password recovery.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What ManoMano customers should do now

  1. Verify every notification independently. Open ManoMano by typing its address or using the official app. Do not use a link in a breach email. A message that mentions your real order can still be fraudulent.
  2. Report suspicious messages. ManoMano says it will not request payment information or account passwords by email, ask for payment through a third party or ask you to download a file from its emails. Forward suspicious messages to [email protected], following its official guidance.
  3. Replace reused passwords. Change a reused or weak ManoMano password everywhere it appears, starting with your email and financial accounts. Use a unique password for each service and enable multifactor authentication where available.
  4. Secure your email account. Review recent sign-ins, recovery addresses and phone numbers, forwarding rules, delegates and connected applications. Email access can enable password resets for many other accounts.
  5. Monitor accounts and payments. Watch for unexpected password-reset messages, new sign-ins, fake refund requests and unauthorized bank or card transactions. Contact your bank or card issuer promptly if you supplied payment information to a scammer or see an unauthorized payment.
  6. Preserve evidence. Keep the original message, screenshots, sender details, telephone numbers, URLs, transaction records and support references. ManoMano’s guidance for people who clicked or disclosed information is available at What if I have answered, clicked on a link or downloaded an attachment?.

If you clicked a link or sent information

Change credentials from a trusted device, beginning with the affected email account, and enable multifactor authentication. If you entered payment details, contact the bank immediately and ask whether the card or account should be blocked. If you downloaded a file, disconnect the device from sensitive accounts while you update security software and follow your device maker’s malware-removal guidance. Preserve the message and report the incident through the relevant national fraud channel.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Should you freeze credit, cancel a card or delete your account?

Credit freeze

A credit freeze is designed to prevent new credit opened with identity information. The reported ManoMano categories do not establish exposure of Social Security numbers or equivalent government identifiers, so a freeze is not an automatic response for every reader. Consider stronger identity-protection steps if your personal notice identifies more sensitive data.

Card cancellation

Do not cancel a card solely because of this incident on the information currently available. Contact the issuer quickly for suspicious transactions or if you gave card details to a scammer.

Account deletion

Deleting a ManoMano account may limit future processing, but it cannot retract data that was already downloaded. Data-subject requests and complaints are separate from eliminating an exfiltrated copy. ManoMano publishes complaint guidance, including escalation to its data-protection contact and CNIL, at its data-protection complaint page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What remains unknown

  • The precise identity of the subcontractor and the initial-access method
  • Whether a Zendesk environment itself was compromised
  • The final number of unique affected people
  • Which specific tickets or attachments were accessed
  • Whether payment information appeared in any individual record
  • Whether the public investigation is complete
  • Any final regulator findings, compensation plan or credit-monitoring offer

An actor calling itself “Indra” claimed responsibility, but that allegation does not prove who accessed the environment or that every claimed record came from ManoMano.

The third-party risk lesson

Customer-service systems often contain richer personal context than a basic account database. Organizations need to limit vendor access to the data and duration required for support, monitor subcontractor accounts, protect attachments and remove access quickly when a provider is no longer needed. The incident alone does not prove which specific control failed, but it illustrates why supplier security and data minimization matter.

Readers can use a breach-notification service such as Have I Been Pwned as an additional signal. A negative result does not prove that a person was unaffected, because third-party databases can be incomplete, delayed or based on unverified material.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.