Toys R Us Canada notified customers that attackers accessed their customer database, stole personal information, and subsequently posted the data online. The breach was discovered on July 30, 2025, after threat actors claimed to have published the stolen data on the unindexed internet. The compromised information includes names, addresses, phone numbers, and email addresses, but does not include passwords, credit card details, or other highly confidential data. The company engaged third-party cybersecurity experts to investigate and contain the incident and is in the process of reporting the breach to Canadian privacy authorities.
Customers have been advised to remain vigilant against phishing attempts and unsolicited communications that may impersonate Toys R Us. While the company has upgraded its IT security systems following the breach, it has not offered free identity or fraud monitoring services to affected individuals. The total number of impacted customers has not been disclosed, but the incident highlights the risks of identity fraud, phishing, and other malicious activities that can result from the exposure of personal information online.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Attackers published the stolen customer data online, escalating the incident from a breach to a public data leak. This online exposure was highlighted in subsequent coverage of the breach.
The company warned customers that their personal information had been compromised in the breach. Multiple outlets reported customer notifications and public disclosure of the incident.
Toys “R” Us Canada experienced a data breach affecting customer personal information. Reporting indicates attackers stole customer data and later exposed it online.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcemobilesyrup.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.