ManoMano·Retail / hospitality·
Customer data was extracted through a compromised third-party provider.
ManoMano confirmed unauthorized extraction of customer data through a compromised third-party provider. The exact technical root cause is not established in the attached record.
Report freshness and timeline
- First publicly reported
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Entry path: Third-party access
- Consequence
- Reported: Customer data was extracted through a compromised third-party provider.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- ManoMano
- Industry
- Retail / hospitality
- Disclosed
- Entry path
- Third-party access
- Third party
- Tunis-based third-party customer support provider
- Affected asset
- Zendesk instance
- Country
- FR
- Data involved
- Personal data
- Reported impact
- Data exposure
- Attached evidence
- 5 independent domains · 5 sources
2)Evidence-backed incident path
- 01
Entry path
Initial access involved third-party access.
ConfidenceSecondaryExact excerpt
E1“a data breach that was caused by hackers compromising a third-party service provider”
bleepingcomputer.com · Feb 26 - 02
Third party
Tunis-based third-party customer support provider
ConfidenceSecondaryExact excerpt
E2“Compromise of a Tunis-based third-party customer support provider”
upguard.com · Feb 26 - 03
Reached
Zendesk instance
ConfidenceSecondaryExact excerpt
E3“unauthorized access to a Zendesk instance”
upguard.com · Feb 26 - 04
Observed
Customer data was extracted through a compromised third-party provider.
ConfidenceProbableExact excerpt
E4“unauthorized extraction of customer data through a compromised third-party provider”
bleepingcomputer.com · Feb 26
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- The exact technical root cause
- That a Defence review would have prevented this incident
4)Relevance to your product
Third-party access can inherit more reach than the product team intended.
This pattern applies when…
- Products that process customer data through support or service providers.
Diagnostic questions
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
This incident does not establish your product's risk.
5)Sector context — Retail / hospitality
- 1 incident threads
- 1 incident threads
- 2 incident threads
- 1 incident threads
- 6 incident threads
- 8 incident threads
- 6 incident threads
- 8 incident threads
- 5 incident threads
- 4 incident threads
- 9 incident threads
- 6 incident threads
- Same incident family
- 17 Supply chain / third party
- Confirmed share
- 32% 18 confirmed · 39 reported
- Display family
- Supply chain Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Retail / hospitality in Radar →6)Defence control mapping
What Defence can test
Third-party integration review
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
7)Public evidence ledger
5 attached sources across 5 independent domains. No attached source is marked as an organization or regulator primary source.
- E1, E4bleepingcomputer.comEuropean DYI chain ManoMano data breach impacts 38 million customersSpecialist reporting · Feb 26 · CitedSpecialist reportingCited
Exact excerpt
“resulted in the unauthorized extraction of certain personal data”
- E2, E3upguard.comOverview: ManoMano Data Breach | UpGuardSecurity research · Feb 26 · CitedSecurity researchCited
Exact excerpt
“customer names, email addresses, phone numbers”
Does this integration boundary exist in your product?
A bounded review can test the authorized web/API path without assuming this incident predicts your risk.