Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
A historical dataset relating to Canada Goose customer transactions was published online; Canada Goose said it had no indication that its own systems were breached. [2]
Impact
A published dataset containing historical e-commerce order information associated with Canada Goose customers. [2]
Documented data types include:
- Purchase history — Order histories, order values, and purchases observed in samples or listed for the HIBP corpus. [1][2]
- Names — Customer names observed in samples and listed for the HIBP corpus. [1][2]
- Contact information — Email addresses, phone numbers, and billing or shipping addresses observed in samples and listed for the HIBP corpus. [1][2]
- Device information — Device and browser information observed in samples and device information listed for the HIBP corpus. [1][2]
- IP addresses — IP addresses observed in samples and listed for the HIBP corpus. [1][2]
- Payment card information — Partial payment-card fields only: samples included card brand, last four digits, sometimes the first six digits, and authorization metadata; no full card numbers were established. [1][2]
A cited record reports 920,000 records (Approximate transaction-record row count described by HIBP, distinct from unique email addresses and affected individuals). [1]
A cited record reports 581,877 records (Unique email addresses represented in the HIBP corpus; not a confirmed count of affected people or customers; as of 2026-02-17). [1][2]
Canada Goose said it was aware that a historical dataset relating to past customer transactions had been published online. [2]
Canada Goose said its review showed no evidence that unmasked financial data was involved. [2]
Canada Goose was reviewing the published dataset to assess its accuracy and scope. [2]
Timeline
Documented activity ended
HIBP BreachDate representing the most recent transaction date in the corpus; not an intrusion date or containment date.
[1]Public disclosure
Date BleepingComputer publicly reported the dataset and Canada Goose’s response; not an asserted intrusion or dataset-publication date.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
Canada Goose said it had no indication of a incident of its own systems. Samples reviewed by BleepingComputer came from a 1.67 GB dataset released in JSON format and contained detailed e-commerce order records. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]
