← ManoMano

2026 ManoMano — 38M accounts via third-party Zendesk (Indra)

2026 38.0M records affected Share on X

Data compromised

Ticket headers, emails, customer messages, invoices, attachments

Technical writeup

ManoMano notified ~38M customers of third-party breach in late Feb 2026. Attackers compromised Tunis-based customer support subcontractor (Zendesk) in Jan 2026. Threat actor 'Indra' claimed ~43GB: 37.8M user accounts, 935K+ service tickets, 13.5K+ attachments. Exposed: names, emails, phones, customer service communications. Passwords not accessed. Company disabled compromised access, revoked subcontractor permissions.

Root cause

Third-party Zendesk compromise; outsourced support agent

References