Mango says some customer information exposed in cyber incident

Spanish fast-fashion retailer Mango said that one of its external marketing service providers suffered a data breach exposing limited customer information, though its own corporate systems were not affected.

In a statement on Tuesday, the company said the compromised data included customers’ first names, countries, postal codes, email addresses and phone numbers, but did not include last names, passwords or financial information such as credit card or banking details.

“Mango’s infrastructure and corporate systems have not been compromised,” the company said, adding that it had notified the Spanish Data Protection Agency (AEPD) and other authorities in line with regulations.

Mango’s top markets include Spain, France and Turkey. The company has dozens of U.S. stores and more than 2,700 worldwide.

The incident is the latest in a string of cyberattacks targeting Spanish and global retailers. In March, El Corte Ingles disclosed that a breach at one of its third-party suppliers exposed customer identification and credit card details. Another Spanish chain, Tendam, was hit by hackers who reportedly stole 720 gigabytes of data and demanded an €800,000 ransom.

Retailers across Europe have also been hit. Earlier this year, Co-op UK said a cyberattack wiped $274 million off its revenues, while Louis Vuitton confirmed breaches at its stores in Turkey, South Korea and the U.K. exposed customer data. Other global brands, including Victoria’s Secret, Dior, Tiffany, and Adidas, have also faced cyber incidents in recent months.

Mango said it detected the incident over the weekend and immediately activated its security protocols. Its online operations were not disrupted.

“We recommend that all our customers pay attention to any suspicious communications or requests for unusual actions, both by email and by phone,” the company added. 

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

 

Total
0
Shares
Previous Post

Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks

Next Post

F5 Breach Exposes BIG-IP Source Code — Nation-State Hackers Behind Massive Intrusion

Related Posts

Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks

New research has uncovered that publishers of over 100 Visual Studio Code (VS Code) extensions leaked access tokens that could be exploited by bad actors to update the extensions, posing a critical software supply chain risk. "A leaked VSCode Marketplace or Open VSX PAT [personal access token] allows an attacker to directly distribute a malicious extension update across the entire install base,"
Read More

China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware

A China-linked advanced persistent threat (APT) group has been attributed to a highly-targeted cyber espionage campaign in which the adversary poisoned Domain Name System (DNS) requests to deliver its signature MgBot backdoor in attacks targeting victims in Türkiye, China, and India. The activity, Kaspersky said, was observed between November 2022 and November 2024. It has been linked to a
Read More

10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and Linux

Cybersecurity researchers have discovered a set of 10 malicious npm packages that are designed to deliver an information stealer targeting Windows, Linux, and macOS systems. "The malware uses four layers of obfuscation to hide its payload, displays a fake CAPTCHA to appear legitimate, fingerprints victims by IP address, and downloads a 24MB PyInstaller-packaged information stealer that harvests
Read More