2024–2025 Manpower (Lansing franchise) — RansomHub-claimed ransomware; ~145k notified
Data compromised
SSN-class, passport/ID images, staffing client metadata, and internal HR/finance documents per notification letters summarized by trade press
Technical writeup
ManpowerGroup stressed corporate network isolation while an independently owned Manpower franchise in Lansing, Michigan investigated a late-December 2024 intrusion detected via January 2025 outage forensics, with Maine regulatory filings ultimately listing roughly 144k affected individuals. BleepingComputer linked the case to RansomHub dark-web marketing of hundreds of gigabytes allegedly holding client dossiers, identity scans, and HR analytics before the listing disappeared.
Root cause
Ransomware and data extortion campaign claimed by RansomHub affiliates against franchise-operated infrastructure
References
- https://www.bleepingcomputer.com/news/security/manpower-staffing-agency-discloses-data-breach-after-attack-claimed-by-ransomhub/
- https://www.hrdive.com/news/manpowergroup-ransomware-attack-leaked-customer-data-staffing-firm-says/757800/
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/7f78311b-64ff-4436-82b7-187ed0d23685.html