DEFENCE / RADAR

Public snapshot

ManoMano·Retail / hospitality·

Customer data was extracted through a compromised third-party provider.

ManoMano confirmed unauthorized extraction of customer data through a compromised third-party provider. The exact technical root cause is not established in the attached record.

Report freshness and timeline

First publicly reported
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Entry path: Third-party access
Consequence
Reported: Customer data was extracted through a compromised third-party provider.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
ManoMano
Industry
Retail / hospitality
Disclosed
Entry path
Third-party access
Third party
Tunis-based third-party customer support provider
Affected asset
Zendesk instance
Country
FR
Data involved
Personal data
Reported impact
Data exposure
Attached evidence
5 independent domains · 5 sources

2)Evidence-backed incident path

  1. 01

    Entry path

    Initial access involved third-party access.

    ConfidenceSecondary
    Exact excerpt

    a data breach that was caused by hackers compromising a third-party service provider

    bleepingcomputer.com · Feb 26
    E1
  2. 02

    Third party

    Tunis-based third-party customer support provider

    ConfidenceSecondary
    Exact excerpt

    Compromise of a Tunis-based third-party customer support provider

    upguard.com · Feb 26
    E2
  3. 03

    Reached

    Zendesk instance

    ConfidenceSecondary
    Exact excerpt

    unauthorized access to a Zendesk instance

    upguard.com · Feb 26
    E3
  4. 04

    Observed

    Customer data was extracted through a compromised third-party provider.

    ConfidenceProbable
    Exact excerpt

    unauthorized extraction of customer data through a compromised third-party provider

    bleepingcomputer.com · Feb 26
    E4

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • The exact technical root cause
  • That a Defence review would have prevented this incident

4)Relevance to your product

Third-party access can inherit more reach than the product team intended.

This pattern applies when…

  • Products that process customer data through support or service providers.

Diagnostic questions

  1. Can an integration reach production secrets or customer data?
  2. Are scopes narrower than the vendor's full workspace access?
  3. Can tokens be isolated and revoked without breaking the product?

This incident does not establish your product's risk.

5)Sector context — Retail / hospitality

57 incident threads in the 365-day public record
  1. 1 incident threads
  2. 1 incident threads
  3. 2 incident threads
  4. 1 incident threads
  5. 6 incident threads
  6. 8 incident threads
  7. 6 incident threads
  8. 8 incident threads
  9. 5 incident threads
  10. 4 incident threads
  11. 9 incident threads
  12. 6 incident threads
Same incident family
17
Supply chain / third party
Confirmed share
32%
18 confirmed · 39 reported
Display family
Supply chain
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Retail / hospitality in Radar →

6)Defence control mapping

What Defence can test

Third-party integration review

  • Can an integration reach production secrets or customer data?
  • Are scopes narrower than the vendor's full workspace access?
  • Can tokens be isolated and revoked without breaking the product?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

5 attached sources across 5 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E1, E4
    bleepingcomputer.comEuropean DYI chain ManoMano data breach impacts 38 million customersSpecialist reporting · Feb 26 · Cited
    Specialist reportingCited
    Exact excerpt
    resulted in the unauthorized extraction of certain personal data
  2. E2, E3
    upguard.comOverview: ManoMano Data Breach | UpGuardSecurity research · Feb 26 · Cited
    Security researchCited
    Exact excerpt
    customer names, email addresses, phone numbers
  3. S3
    securityaffairs.comManoMano data breach impacted 38 Million customer accountsSpecialist reporting · Feb 27 · Attached
    Specialist reportingAttached
  4. S4
    gblock.app38 Million Europeans Had Their Emails and Phone Numbers Stolen—Via a Customer Support AppOther public report · Mar 01 · Attached
    Other public reportAttached
  5. S5
    rescana.comManoMano Zendesk Data Breach Exposes 38 Million Customers Across Europe: Incident Analysis and Security ImplicationsOther public report · Mar 01 · Attached
    Other public reportAttached

Does this integration boundary exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →