ShinyHunters published a 1.67 GB dataset allegedly containing 600,000+ Canada Goose customer records on its data leak site, positioning the release as stolen e-commerce data tied to customer orders. Canada Goose said it is aware of the publication of a historical dataset related to past transactions and stated it has no indication of a breach of its own systems, while it continues to review the dataset’s accuracy and scope and determine whether customer notifications are required.
Samples reviewed indicate the leak contains detailed order and customer information, including names, email addresses, phone numbers, billing/shipping addresses, IP addresses, order histories/values, and device/browser details, along with partial payment card data (e.g., card brand, last four digits, and in some cases BIN/first six digits) plus payment authorization metadata. Canada Goose stated its review shows no evidence of unmasked financial data being involved, but the exposed personal and transaction context could still enable targeted phishing, social engineering, and fraud against affected customers.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Have I Been Pwned added the incident as a breach entry, reporting 920,000 records and 582,000 unique email addresses in the publicly released dataset. The listing reiterated Canada Goose's position that the data related to past transactions and likely stemmed from a third-party breach in August 2025.
Journalists who reviewed samples of the leaked JSON data reported that it included names, contact details, addresses, order histories, device/browser information, and partial payment card metadata such as last four digits and sometimes BIN data. These reviews supported that the leak exposed substantial customer information even though full card numbers were not observed.
After the leak was publicized, Canada Goose said the published data appears to be a historical dataset tied to past transactions and that it found no evidence its own systems had been breached. The company also said its review showed no unmasked financial data was involved and that it was assessing the dataset's scope and accuracy.
On February 14, 2026, ShinyHunters published a 1.67 GB dataset on its leak site, claiming it contained more than 600,000 Canada Goose customer records with PII, order details, and partial payment information. Multiple reports described the dump as historical transaction data tied to Canada Goose customers.
Canada Goose and ShinyHunters both said the exposed customer data originated from a third-party payment processor breach that allegedly occurred in August 2025. This attribution was reported later and was not independently verified in the referenced coverage.
Analysis later cited by Have I Been Pwned found the newest transaction in the leaked Canada Goose data was dated July 2025. This timing was presented as consistent with Canada Goose's claim that the data was historical rather than from a recent intrusion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
rescana.com
Open sourcetherecord.media
Open sourcesecurityaffairs.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.