Canada Goose historical customer dataset publication

A historical dataset relating to Canada Goose customer transactions was published online; Canada Goose said it had no indication that its own systems were breached. A published dataset containing historical e-commerce order information associated with Canada Goose customers.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

A historical dataset relating to Canada Goose customer transactions was published online; Canada Goose said it had no indication that its own systems were breached. [2]

Impact

A published dataset containing historical e-commerce order information associated with Canada Goose customers. [2]

Documented data types include:

  • Purchase history — Order histories, order values, and purchases observed in samples or listed for the HIBP corpus. [1][2]
  • Names — Customer names observed in samples and listed for the HIBP corpus. [1][2]
  • Contact information — Email addresses, phone numbers, and billing or shipping addresses observed in samples and listed for the HIBP corpus. [1][2]
  • Device information — Device and browser information observed in samples and device information listed for the HIBP corpus. [1][2]
  • IP addresses — IP addresses observed in samples and listed for the HIBP corpus. [1][2]
  • Payment card information — Partial payment-card fields only: samples included card brand, last four digits, sometimes the first six digits, and authorization metadata; no full card numbers were established. [1][2]

A cited record reports 920,000 records (Approximate transaction-record row count described by HIBP, distinct from unique email addresses and affected individuals). [1]

A cited record reports 581,877 records (Unique email addresses represented in the HIBP corpus; not a confirmed count of affected people or customers; as of 2026-02-17). [1][2]

Canada Goose said it was aware that a historical dataset relating to past customer transactions had been published online. [2]

Canada Goose said its review showed no evidence that unmasked financial data was involved. [2]

Canada Goose was reviewing the published dataset to assess its accuracy and scope. [2]

Timeline

  1. Documented activity ended

    HIBP BreachDate representing the most recent transaction date in the corpus; not an intrusion date or containment date.

    [1]
  2. Public disclosure

    Date BleepingComputer publicly reported the dataset and Canada Goose’s response; not an asserted intrusion or dataset-publication date.

    [2]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Canada Goose said it had no indication of a incident of its own systems. Samples reviewed by BleepingComputer came from a 1.67 GB dataset released in JSON format and contained detailed e-commerce order records. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]