Canadian Tire says recent data breach may have hit online shoppers’ info
Unauthorized access was identified on October 2, 2025 in an e‑commerce database for Canadian Tire, SportChek, Mark’s/L’Équipeur, and Party City. The dataset included names, addresses, emails, birth years, encrypted passwords, and in some cases truncated card numbers. Fewer than 150,000 accounts had full dates of birth. Bank and Triangle Rewards records were reported as not included, and in‑store transactions continued.

What was involved?
-
Confirmed within the e‑commerce database.
-
Stored in encrypted form; password reuse remains unsafe practice.
-
Comparable to receipt formatting; full numbers were not present.
-
Included for fewer than 150,000 accounts; eligible customers are to receive credit monitoring offers.
-
Reported as not included in this event.
Password habit check
Where accounts exist
E‑commerce accounts with any listed banner could be in scope.
30‑second check
Were full dates of birth present for all accounts?
Were bank or Triangle Rewards records included?
What card data format was referenced?
Further reading & related coverage
- Qantas dark‑web leak and ransom context
- Gmail users: breach & phishing risk
- Jaguar Land Rover cyberattack case
- Phishing detection & multitasking research
- AT&T breach settlement overview
- iiNet breach: actions to consider
- Messaging app safety notes
- Aviation incident & manual check‑ins
- LAX ground stop equipment outage
- SpinOK Android malware spread
- 23andMe: data risk context
- Facebook privacy settlement
External link provided: related post on X.