Manpower of Lansing, an independently owned Michigan franchise, reported that unauthorized access to an external system affected 144,189 people. The incident was not reported as a breach of ManpowerGroup’s corporate network. Affected individuals were offered 12 months of Equifax credit monitoring and identity-theft protection through Epiq.
What happened
The affected legal entity is Manpower of Lansing, MI Inc., listed at 741 N. Cedar St. in Lansing, Michigan. According to its filing with the Maine Attorney General, attackers gained unauthorized access to an external system between December 29, 2024, and January 12, 2025.
The filing describes the event as an external-system hacking incident. It lists 144,189 affected people, including 11 Maine residents. Manpower of Lansing said it determined that personal information may have been involved on or about July 28, 2025.
This is a franchise incident, not a confirmed companywide ManpowerGroup breach. ManpowerGroup told BleepingComputer that the Lansing operation used an independent data platform and that ManpowerGroup’s corporate systems were not affected.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
Timeline
| Date | What happened |
|---|---|
| December 29, 2024 | Beginning of the unauthorized-access period identified in the notification. |
| January 12, 2025 | End of the access period listed in the filing. |
| January 20, 2025 | The Lansing franchise began investigating after an IT-systems outage, according to BleepingComputer. |
| July 28, 2025 | Manpower of Lansing determined that personal information may have been involved. |
| August 11, 2025 | Written notices were sent to affected consumers. |
| August 12–13, 2025 | BleepingComputer reported the incident and then added ManpowerGroup’s clarification about the franchise and corporate network. |
What information may have been exposed?
Confirmed by the breach filing
The Maine filing confirms that personal information may have been involved, but the available filing record does not provide a complete, person-by-person inventory of data elements. Exposure therefore may differ among individuals. The notification letter sent to each person is the controlling source for what information was associated with that person’s records.
Claimed by RansomHub
The RansomHub ransomware operation claimed responsibility and alleged that it took about 500 GB of data. BleepingComputer reported the group’s claimed list as including passport scans, identity documents, Social Security numbers, addresses, contact information, test results, financial statements, human-resources analytics, client databases, corporate correspondence, contracts and nondisclosure agreements.
Those are threat-actor claims, not an independently verified inventory for all 144,189 people. Manpower did not publicly confirm that RansomHub was the attacker or that every listed category was exposed.
Was this a ransomware attack?
RansomHub claimed the attack in January 2025, but the available company reporting does not establish attribution. The alleged listing was later removed from RansomHub’s leak site. Removal does not prove that a ransom was paid, and no ransom payment has been established by the cited sources.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #3
Did the breach affect ManpowerGroup?
ManpowerGroup includes Manpower, Experis and Talent Solutions, but the reported affected entity was the independently owned and operated Lansing franchise. ManpowerGroup said the franchise operated on a separate data platform and that its corporate network was not affected. The parent company said it was supporting the franchise while the franchise managed the direct response.
How were people notified?
The Maine filing says written notices dated August 11, 2025, were sent to affected consumers. Use your own letter or email—not a generic online message—to determine whether you are included and which data categories apply.
- Check that the notice identifies Manpower of Lansing or the relevant franchise.
- Use only the enrollment link, activation code and telephone number printed in the notice.
- Do not provide unnecessary passwords or payment-card details to enroll.
- Be cautious of unsolicited callers or messages claiming to provide breach assistance.
What assistance was offered?
The incident-specific offer provides 12 months of Equifax credit monitoring and identity-theft protection, administered by Epiq. The Maine filing lists:
- Daily access to an Equifax credit report
- WebScan notifications
- Fraud alerts
- Fully managed identity-recovery services
- A $1 million insurance reimbursement policy
This is a benefit tied to the breach notice. Buying a separate Equifax subscription is not required to use the service described in your letter.
Best Value
What affected people should do now
- Read and preserve the notice. Confirm that you are specifically identified and note the enrollment deadline and covered data categories.
- Enroll through the official process. Use the instructions supplied by Manpower of Lansing or Epiq, not a link in an unsolicited message.
- Review all three credit reports. Look for unfamiliar accounts, inquiries, addresses or other changes. Monitoring alerts activity; it does not prevent a new account from being opened.
- Consider a credit freeze. A freeze generally provides stronger protection against new-account fraud when you do not expect to apply for credit soon. You can still use the offered monitoring while your files are frozen.
- Choose a fraud alert when convenience matters. A fraud alert asks creditors to take additional identity-verification steps and may be more convenient if you expect to apply for credit soon.
- Change reused passwords and enable multifactor authentication. Prioritize email, banking, payroll, tax and other high-value accounts. The available sources do not confirm that passwords were exposed.
- Watch for employment-themed phishing. Staffing records can make fake payroll, job, benefits or identity-verification messages appear credible.
- Act quickly on suspicious activity. Contact the financial institution through a verified channel and use official government identity-theft reporting resources.
If your Social Security number may be involved
Because Social Security-number exposure was reported as a RansomHub claim rather than fully itemized in the Maine filing record, treat this as a conditional precaution. Consider freezing your files with Equifax, Experian and TransUnion, review tax and employment-account activity, and watch for fraudulent unemployment, payroll, tax or benefits claims. Do not give an SSN to a caller who says they are following up on the breach unless you independently verify the caller.
If you were not notified
Having applied to, worked for, contracted with or dealt with Manpower does not by itself prove that your records were among the 144,189 affected. Contact the franchise through a phone number from a prior legitimate record or an official Manpower channel—not a number in a suspicious message—and ask whether your records were included. If you have a reasonable concern, review your credit reports and account activity anyway.
What remains unknown
- Whether RansomHub was the actual attacker
- Whether any ransom was paid
- The complete confirmed list of data elements involved
- Whether all alleged data was publicly released
- Whether later investigation identifies additional people or systems
Optional paid identity-protection services from companies such as Experian, TransUnion or Aura may provide longer-term or broader monitoring, but they can duplicate the free 12-month benefit. A credit freeze remains free and may offer more direct protection against new-account fraud.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →




