ManoMano, the French online DIY and home improvement marketplace, has confirmed that customer data was accessed following a cyberattack on one of its customer service subcontractors.
Some reports suggest the incident may affect tens of millions of users across Europe – including the UK.
If you’ve used ManoMano to buy tools, garden equipment or home improvement products, here’s what we know so far, what could be at risk, and what you can do next.
What happened in the ManoMano breach?
According to multiple reports, the breach occurred in January 2026 and involved a customer support provider used by ManoMano.
The company has told customers that:
- An unauthorised download of personal data took place
- The incident related to a subcontractor’s customer service account
- Passwords were not affected
- The issue has been reported to France’s data protection authority (CNIL) and national cybersecurity agency (ANSSI)
Some reports suggest the platform involved may have been Zendesk, a widely used customer support system.
A threat actor calling themselves “Indra” has claimed responsibility on an underground forum, alleging that approximately 37.8 million user accounts were affected and around 43GB of data was taken.
What data may have been exposed?
The exposed data may include:
- Names
- Email addresses
- Phone numbers
- Customer service conversations
- Support ticket metadata
- Attachments shared with customer support
ManoMano has said passwords were not impacted. However, support tickets can contain sensitive details such as order information, delivery addresses, invoices or screenshots.
That context can be extremely valuable to fraudsters.
Could UK customers be affected?
Because the breach involved a third-party support provider used across multiple ManoMano sites, it may have affected customers in more than one country, including:
- France
- Spain
- Italy
- Germany
- United Kingdom
ManoMano operates at www.manomano.co.uk, and UK users who have contacted customer support could potentially be included in the compromised data. If you are based in the UK and have received a notification from ManoMano, you should take it seriously.
Why support ticket breaches are risky
When people think about data breaches, they often focus on passwords or payment details. But customer service tickets often contain:
- Order histories
- Personal explanations of issues
- Screenshots
- Internal escalation notes
- Email trails
That kind of information can be highly sensitive. Even if passwords were not taken, criminals can use exposed contact details and conversation history to build trust.
If your data was included, potential risks may include:
- Targeted phishing emails
- Impersonation scams
- Fraud attempts referencing real orders
- Increased spam or scam calls
For example, a fraudster might reference a genuine support case you raised months ago.
That familiarity makes scams harder to spot.
What should you do now?
If you have used ManoMano in the UK:
- Check your inbox (and spam folder) for any official notification.
- Be cautious of emails referencing past ManoMano support cases
- Do not click unexpected links or download attachments
- Consider updating your ManoMano password as a precaution
- Use unique passwords across different platforms
- Enable two-factor authentication wherever possible.
Your rights under UK GDPR
Under UK GDPR and the Data Protection Act 2018, organisations must keep personal data secure. If a company fails to implement appropriate security measures and that failure leads to unauthorised access, affected individuals may be entitled to claim compensation.
Each case depends on the facts. Not every breach results in compensation. But where there is evidence of inadequate safeguards, legal action may follow.
Join the Claim connects consumers with SRA-regulated lawyers. Visit the claim page to check your eligibility if a claim is open with one of our trusted legal partners. If a group action has not yet been launched, you can register your interest and we’ll keep you informed if a partner firm decides to take a claim forward.