ManoMano Incident · 2 February 2026

Customer details and support messages taken from a customer service subcontractor

38 million people affected

ManoMano, an online DIY marketplace, told customers in early February 2026 that personal data had been taken through the compromised account of an agent at one of its customer service subcontractors. It said it identified the access in January. ManoMano told BleepingComputer the data varies by person and includes full names, email addresses, phone numbers and customer service communications, and that no passwords were accessed. BleepingComputer reported that 38 million people are affected; a hacker calling themselves Indra claimed 37.8 million accounts. ManoMano said it cut the subcontractor's access and notified France's CNIL and ANSSI. Unconfirmed reports name a support firm in Tunis and its Zendesk account.

affected · A subcontracted customer service provider with access to customer accounts and support exchanges

Before it happened
If you'd stopped using them
A deletion request, sent when you left, asks them to delete what they hold. If they had, less of yours would have been in what was taken.
If you still used them
A limit request asks them to stop using your data for marketing, for sharing with partners, and for research or profiling.

Their reply would have been their claim, dated, and yours to point to now.

More events

The rest of the wire, newest first.

ASOS

Notice 8 Oct 2026

Notice October 2026

Customer profiles with addresses and site searches taken through a phished staff login

ASOS emailed customers on 8 October 2026 that someone "impersonating a trusted contact" got an employee's login and used it "to access information on certain third-party platforms used by Asos". A sample the attackers sent to BBC News holds names, addresses, phone numbers, emails, customer numbers and searches made on the site. Searches next to a name and an email are a record of what someone was looking at, including things they might never tell anyone. The attackers claimed to the BBC they got in through Simon AI, a marketing data platform. ASOS has named no platform; Simon AI's website lists ASOS as a customer. ASOS has given no numbers.

Notice · Retail

ASOS

Incident 6 Oct 2026

Incident October 2026

Attackers sent a push alert through its own app, threatening to leak its data

At about 10am on 6 October 2026, ASOS customers received a push notification through its app from attackers who said they had "fully compromised the Snowflake instance" and threatened to leak it. ASOS told the London Stock Exchange that day it was investigating unauthorised activity on "third-party platforms that we use to communicate with customers" and that "basic personal information including name and contact details may have been accessed". It said it did not believe payment card details or passwords were affected. Snowflake said its own platform had not been breached. The UK's National Cyber Security Centre tells every ASOS customer to assume they are affected, even without the notification.

Incident · Retail

Geon Media

Notice 29 Sept 2026

413,576 names on the rental list

Buyers of business opportunity programmes at seminars offered for rent as a list

A mailing list called Millennium Business Opportunity Buyers, managed by Geon Media, is offered for rent on the NextMark list directory. Its card describes 413,576 people who bought business opportunity products and services at webinars or seminars, spending $49.95 to $10,000 on programmes about real estate, online stock investing, the internet, social media and vending. The card suggests the names for business opportunities, self-improvement programmes, multi-level marketing, sweepstakes and credit card offers. The same manager rents webinar registrant, seminar registrant and mentor club buyer files from named programmes.

Notice · Advertising & Marketing