Third-party breach, 38M impacted, European e-commerce sector.
ManoMano disclosed unauthorized access linked to a subcontracted customer support provider. Exposed data reportedly includes PII and support communications.
Authorities notified: CNIL, ANSSI.
Passwords not reportedly accessed.
Subcontractor access revoked.

Key risk vectors:
– SaaS support platforms
– Vendor access governance
– Over-retention of ticketing data
– Centralized customer communication logs
– Supply chain attack surface expansion

This case reinforces that vendor monitoring must go beyond contractual clauses — continuous assessment, least privilege enforcement, data minimization strategies.

How mature is your third-party risk telemetry?
Engage below.

Source: https://www.bleepingcomputer.com/news/security/european-dyi-chain-manomano-data-breach-impacts-38-million-customers/

Follow @technadu for high-signal infosec reporting.

Repost to amplify awareness across the security community.

#Infosec #ThirdPartyRisk #VendorSecurity #SupplyChainSecurity #DataBreach #GDPRCompliance #EcommerceSecurity #CyberRiskManagement #SecurityOperations #GRC

Coupang confirms a data breach exposing customer information — e-commerce speed means nothing without security at scale. Trust must ship with every order. 📦🔓 #EcommerceSecurity #DataProtection

https://www.theregister.com/2025/12/01/coupang_breach/

South Korea's answer to Amazon admits breach exposed 33.7M customers

: Coupang confirms internationally routed intrusion compromised more than half of the country's population

The Register
Initial access attempts have been observed targeting gg portals in Nepal 🇳🇵, specifically focusing on the e-commerce and online stores sector. Confidence in this activity is high. #CyberThreat #EcommerceSecurity #ThreatIntel

Peak shopping season is almost here 🎯, and for many online stores, the real challenge isn’t scale, it’s security.

ScaleCommerce, a leading e-commerce hosting provider in Germany, once saw clients hit with 3 million requests in an hour, driving up costs and risking downtime.

After integrating CrowdSec, they were able to block 95% of malicious bot traffic, cut infrastructure spend, and keep sites fast during peak demand ⚡️.

As the year’s biggest shopping weekend approaches, make sure your traffic surge comes from real customers, not attacks.

Read the full story: https://www.crowdsec.net/blog/scalecommerce-plummets-ops-costs-and-skyrockets-efficiency

#cybersecurity #ecommercesecurity #blackfriday2025 #botprotection

Cloudflare partners with Visa and Mastercard to secure AI agent shopping: Cloudflare, Visa and Mastercard introduce authentication protocols to help merchants distinguish legitimate AI shopping agents from malicious bots through cryptographic verification. https://ppc.land/cloudflare-partners-with-visa-and-mastercard-to-secure-ai-agent-shopping/ #Cloudflare #Visa #Mastercard #AIShopping #EcommerceSecurity
Cloudflare partners with Visa and Mastercard to secure AI agent shopping

Cloudflare, Visa and Mastercard introduce authentication protocols to help merchants distinguish legitimate AI shopping agents from malicious bots through cryptographic verification.

PPC Land

A dangerous flaw in Adobe Commerce lets hackers hijack customer sessions with zero effort—and 60% of Magento stores are still unpatched. Is your business vulnerable?

https://thedefendopsdiaries.com/understanding-and-responding-to-the-sessionreaper-vulnerability-in-adobe-commerce/

#sessionreaper
#adobecommerce
#magento
#cve202554236
#ecommercesecurity

🚨 Critical Magento & Adobe Commerce Flaw (CVE-2025-54236 – SessionReaper) 🚨

Impact: Customer account takeover + unauthenticated remote code execution (CVSS 9.1 Critical).

👉 Full details and action steps: https://hostvix.com/sessionreaper-critical-magento-adobe-commerce-vulnerability-cve-2025-54236/

#Magento #AdobeCommerce #SessionReaper #CVE202554236 #CVE #Infosec #CyberSecurity #AppSec #WebSecurity #SecOps #BlueTeam #RedTeam #ThreatIntel #Vulnerability #PatchNow #ZeroDay #Exploit #EcommerceSecurity #DataSecurity #SecurityUpdate

SessionReaper: Critical Magento & Adobe Commerce Vulnerability (CVE-2025-54236) - Hostvix

Adobe Commerce and Magento Open Source have been hit by a vulnerability called SessionReaper (CVE-2025-54236). This bug allows attackers not only to take over customer accounts but also — under certain conditions — to execute malicious code remotely. Sansec Forensics, who analyzed the issue, warn that this vulnerability is among the most severe in Magento’s...

Hostvix
Riskified & Human Security are joining forces to help #ecommerce merchants manage agentic AI risks. https://jpmellojr.blogspot.com/2025/08/new-framework-targets-fraud-from.html #AgenticAI #EcommerceSecurity #FraudPrevention #AIrisks

🛍️ Online shopping scams are on the rise—watch for fake sites, too-good-to-be-true deals, and suspicious payment methods. Stay smart, shop safe.
#OnlineFraud #EcommerceSecurity 🕵️‍♂️💳

https://www.helpnetsecurity.com/2025/07/10/tips-online-shopping-scams/

Fake online stores look real, rank high, and trap unsuspecting buyers - Help Net Security

Learn how cybercriminals create fake online stores in online shopping scams to trick consumers into sharing personal info or sending money.

Help Net Security

🕵️‍♂️ Someone just got a Cartier watch for $0. How? With disappearing ink.
In our new video, we break down a real scam that costs businesses thousands.

Learn how it works – and how to protect your company 👉

https://youtu.be/WaS9tuD7qtU

#CyberSecurity #Neuronus #FraudAlert #EcommerceSecurity #BusinessTips

How to Get a Cartier Watch for Free – The Disappearing Ink Scam Exposed!

YouTube