Tuesday, December 16, 2025
26.5 F
New York

Sensitive customer info exposed in Mango data breach – here

hacker hands at work with interface around
(Image credit: Shutterstock)

  • Mango suffered a third-party breach exposing customer details, but no financial data
  • Notifications warn of phishing risks; Spanish authorities & police informed
  • ShinyHunters, known data extortion group, may be linked to recent retail sector breaches

Retail powerhouse Mango, a firm with more than 2,500 stores worldwide and operates in more than 120 markets, has suffered a third party data breach, losing sensitive customer information on a yet-undisclosed number of customers.

Earlier this week, the company sent out data breach notifications to its customers, warning them about potential incoming social engineering and other attacks. In the breach, Mango said that certain personal data was accessed through a breach at one of its external marketing services providers.

The attackers, which have not been named, stole people’s first names (surnames were not grabbed), countries, postal codes, email addresses, and phone numbers. Sensitive financial information, such as banking data, credit card information, IDs or passports, as well as login credentials and passwords, were not compromised, Mango stressed.

Was it ShinyHunters?

The company continues to operate normally and confirms its infrastructure was not breached or compromised in any way. The attack triggered the company’s usual security protocols, including notifying the Spanish Data Protection Agency (AEPD), as well as law enforcement.

For Raghu Nandakumara, VP of Industry Strategy at Illumio, the recent string of attacks on retailers shows how these companies do not sufficiently assess third party suppliers: “Organizations still place far too much implicit trust in their suppliers, with research showing fewer organizations are concerned now about ransomware risks from their supply chains,” he explained.

“They must focus on containing and limiting the impact of attacks to ensure threats are stopped in their tracks before they can cripple essential services and expose sensitive data.”

Mango did not say who the breached third party is, or what it does in relation to the retailer. It also did not name the attackers or discuss the nature of the breach.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

However, a group known as ShinyHunters has been targeting major retailers for the past couple of months, breaching M&S, Harrods, Coop, and plenty of other retailers. Kering, the parent company of Gucci, Balenciaga, and others, was among the targets, as well.

ShinyHunters are primarily a ransomware group that doesn’t deploy an encryptor on its targets’ servers, but rather simply exfiltrates sensitive data and then demands payment in cryptocurrency in exchange for deleting the stolen files. If the demands aren’t met, the data gets leaked on the internet, which could put the victim in the crosshairs of data watchdogs, and could lead to class action lawsuits.

Via Cybernews


Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Hot this week

Stop avoiding your bank balance and other ways to manage your money better

BBC We've all looked at our bank account and wondered...

Railways: Firms develop new tech to electrify trains

'This is the big one' - tech firms bet...

UK targets 420m at sky high industry energy bills

£420m bill cut for heavy industry as union attacks...

Apple claims ‘tremendous’ global uptake of latest iPhones

Danielle KayeBusiness reporter Reuters Apple boss Tim Cook holds an iPhone...

Trump hails ‘amazing’ meeting with Xi in South Korea

Trump hails 'amazing' meeting with China's Xi but no...

Topics

Stop avoiding your bank balance and other ways to manage your money better

BBC We've all looked at our bank account and wondered...

Railways: Firms develop new tech to electrify trains

'This is the big one' - tech firms bet...

UK targets 420m at sky high industry energy bills

£420m bill cut for heavy industry as union attacks...

Apple claims ‘tremendous’ global uptake of latest iPhones

Danielle KayeBusiness reporter Reuters Apple boss Tim Cook holds an iPhone...

Trump hails ‘amazing’ meeting with Xi in South Korea

Trump hails 'amazing' meeting with China's Xi but no...

Ofcom slams O2 over unexpected mobile phone contract price rise

Imran Rahman-JonesTechnology reporter The UK's media regulator has criticised O2...

Virgin cleared to challenge Eurostar on Channel Tunnel route

Charlotte EdwardsBusiness reporter Virgin Trains has moved closer to being...

US and China’s different reports of their trade meeting

Skip to content British Broadcasting Corporation Home News Sport Business Innovation Culture Arts Travel Earth Audio Video Live More on this story. 23 hours...

Related Articles

Popular Categories

Previous article
Next article