Data leak in the Mango store. Customers at risk of attacks

2025-10-17 10:15
publication
2025-10-17 10:15
The Mango online store became the target of a hacker attack, as a result of which contact details of customers from various countries were disclosed. According to the FashionBiznes portal, a security incident occurred at the Spanish company, but the company reassures that the leak does not concern sensitive user information.
Information about the leak appeared in foreign media, but Mango has not yet commented on the situation in an official statement. Notifications about the security breach were sent to customers on October 15, and we learn from them that the attack was carried out not directly on the store's servers, but on the infrastructure of an external company dealing with marketing communications.


What was the leak at the Mango store about?
According to FashionBiznes.pl, the leak included data used by the brand in marketing campaigns, specifically:
- name (without surname),
- phone number,
- email address,
- zip code,
- country.
Mango emphasizes that sensitive data, such as banking information, store account logins and passwords, or identity documents, were not disclosed, and the corporate infrastructure and systems of the brand itself were not breached. Immediately after detecting the attack, the store initiated security procedures and notified the Spanish Data Protection Agency (AEPD), but it is not known what the scale of the leak was and exactly in which company it occurred.
What can Mango customers in Poland do?
In the event of any cyber attack that results in the disclosure of data in an e-store, customers are asked to be particularly careful with the e-mails and telephone calls they receive. Contact details may be used by fraudsters to impersonate Mango in order to extort further information, e.g. to log in to electronic banking (phishing).
If you shopped at Mango, check your emails for data leaks and consider changing your account password. It is worth being vigilant against unusual e-mails, calls from unknown numbers and text messages encouraging you to click on suspicious links.
Prepared by AD




