Data leak
MANGO Third-Party Marketing Provider Breach
Primary Source βIncident Details
MANGO, the Spanish global fashion retailer, disclosed in October 2025 that a third-party marketing provider had been compromised, exposing customer data. Exposed information included customer first names, countries of residence, postal codes, email addresses, and phone numbers. MANGO notified affected customers and filed notifications with relevant European data protection authorities. The breach did not expose payment information or full postal addresses.
Technical Details
- Initial Attack Vector
- MANGO's third-party marketing service provider was compromised, exposing customer contact and demographic data used for marketing campaigns
Timeline
- 2025-09-15 Breach occurred
- 2025-10-10 Publicly disclosed
- 2025-10-10 Customers notified