Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Manpower of Lansing Data Breach Affects 144,189 People

A Michigan Manpower franchise reported unauthorized access affecting 144,189 people. Here is what is confirmed, what RansomHub only alleged, and what affected readers should do.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Manpower of Lansing, an independently owned Michigan franchise, reported that unauthorized access to an external system affected 144,189 people. The incident was not reported as a breach of ManpowerGroup’s corporate network. Affected individuals were offered 12 months of Equifax credit monitoring and identity-theft protection through Epiq.

What happened

The affected legal entity is Manpower of Lansing, MI Inc., listed at 741 N. Cedar St. in Lansing, Michigan. According to its filing with the Maine Attorney General, attackers gained unauthorized access to an external system between December 29, 2024, and January 12, 2025.

The filing describes the event as an external-system hacking incident. It lists 144,189 affected people, including 11 Maine residents. Manpower of Lansing said it determined that personal information may have been involved on or about July 28, 2025.

This is a franchise incident, not a confirmed companywide ManpowerGroup breach. ManpowerGroup told BleepingComputer that the Lansing operation used an independent data platform and that ManpowerGroup’s corporate systems were not affected.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Timeline

Date What happened
December 29, 2024 Beginning of the unauthorized-access period identified in the notification.
January 12, 2025 End of the access period listed in the filing.
January 20, 2025 The Lansing franchise began investigating after an IT-systems outage, according to BleepingComputer.
July 28, 2025 Manpower of Lansing determined that personal information may have been involved.
August 11, 2025 Written notices were sent to affected consumers.
August 12–13, 2025 BleepingComputer reported the incident and then added ManpowerGroup’s clarification about the franchise and corporate network.

What information may have been exposed?

Confirmed by the breach filing

The Maine filing confirms that personal information may have been involved, but the available filing record does not provide a complete, person-by-person inventory of data elements. Exposure therefore may differ among individuals. The notification letter sent to each person is the controlling source for what information was associated with that person’s records.

Claimed by RansomHub

The RansomHub ransomware operation claimed responsibility and alleged that it took about 500 GB of data. BleepingComputer reported the group’s claimed list as including passport scans, identity documents, Social Security numbers, addresses, contact information, test results, financial statements, human-resources analytics, client databases, corporate correspondence, contracts and nondisclosure agreements.

Those are threat-actor claims, not an independently verified inventory for all 144,189 people. Manpower did not publicly confirm that RansomHub was the attacker or that every listed category was exposed.

Was this a ransomware attack?

RansomHub claimed the attack in January 2025, but the available company reporting does not establish attribution. The alleged listing was later removed from RansomHub’s leak site. Removal does not prove that a ransom was paid, and no ransom payment has been established by the cited sources.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Did the breach affect ManpowerGroup?

ManpowerGroup includes Manpower, Experis and Talent Solutions, but the reported affected entity was the independently owned and operated Lansing franchise. ManpowerGroup said the franchise operated on a separate data platform and that its corporate network was not affected. The parent company said it was supporting the franchise while the franchise managed the direct response.

How were people notified?

The Maine filing says written notices dated August 11, 2025, were sent to affected consumers. Use your own letter or email—not a generic online message—to determine whether you are included and which data categories apply.

  • Check that the notice identifies Manpower of Lansing or the relevant franchise.
  • Use only the enrollment link, activation code and telephone number printed in the notice.
  • Do not provide unnecessary passwords or payment-card details to enroll.
  • Be cautious of unsolicited callers or messages claiming to provide breach assistance.

What assistance was offered?

The incident-specific offer provides 12 months of Equifax credit monitoring and identity-theft protection, administered by Epiq. The Maine filing lists:

  • Daily access to an Equifax credit report
  • WebScan notifications
  • Fraud alerts
  • Fully managed identity-recovery services
  • A $1 million insurance reimbursement policy

This is a benefit tied to the breach notice. Buying a separate Equifax subscription is not required to use the service described in your letter.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What affected people should do now

  1. Read and preserve the notice. Confirm that you are specifically identified and note the enrollment deadline and covered data categories.
  2. Enroll through the official process. Use the instructions supplied by Manpower of Lansing or Epiq, not a link in an unsolicited message.
  3. Review all three credit reports. Look for unfamiliar accounts, inquiries, addresses or other changes. Monitoring alerts activity; it does not prevent a new account from being opened.
  4. Consider a credit freeze. A freeze generally provides stronger protection against new-account fraud when you do not expect to apply for credit soon. You can still use the offered monitoring while your files are frozen.
  5. Choose a fraud alert when convenience matters. A fraud alert asks creditors to take additional identity-verification steps and may be more convenient if you expect to apply for credit soon.
  6. Change reused passwords and enable multifactor authentication. Prioritize email, banking, payroll, tax and other high-value accounts. The available sources do not confirm that passwords were exposed.
  7. Watch for employment-themed phishing. Staffing records can make fake payroll, job, benefits or identity-verification messages appear credible.
  8. Act quickly on suspicious activity. Contact the financial institution through a verified channel and use official government identity-theft reporting resources.

If your Social Security number may be involved

Because Social Security-number exposure was reported as a RansomHub claim rather than fully itemized in the Maine filing record, treat this as a conditional precaution. Consider freezing your files with Equifax, Experian and TransUnion, review tax and employment-account activity, and watch for fraudulent unemployment, payroll, tax or benefits claims. Do not give an SSN to a caller who says they are following up on the breach unless you independently verify the caller.

If you were not notified

Having applied to, worked for, contracted with or dealt with Manpower does not by itself prove that your records were among the 144,189 affected. Contact the franchise through a phone number from a prior legitimate record or an official Manpower channel—not a number in a suspicious message—and ask whether your records were included. If you have a reasonable concern, review your credit reports and account activity anyway.

What remains unknown

  • Whether RansomHub was the actual attacker
  • Whether any ransom was paid
  • The complete confirmed list of data elements involved
  • Whether all alleged data was publicly released
  • Whether later investigation identifies additional people or systems

Optional paid identity-protection services from companies such as Experian, TransUnion or Aura may provide longer-term or broader monitoring, but they can duplicate the free 12-month benefit. A credit freeze remains free and may offer more direct protection against new-account fraud.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.