---
title: "Canada Goose historical customer dataset publication"
description: "Evidence-backed account of Canada Goose historical customer dataset publication, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/canada-goose-historical-customer-dataset-publication-2026"
markdown_url: "https://www.ally.security/incidents/canada-goose-historical-customer-dataset-publication-2026.md"
stix_url: "https://www.ally.security/incidents/canada-goose-historical-customer-dataset-publication-2026/stix.json"
---

# Canada Goose historical customer dataset publication

A historical dataset relating to Canada Goose customer transactions was published online; Canada Goose said it had no indication that its own systems were breached. A published dataset containing historical e-commerce order information associated with Canada Goose customers.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

A historical dataset relating to [Canada Goose](https://www.canadagoose.com/) customer transactions was published online; Canada Goose said it had no indication that its own systems were breached. [2](#source-2)

## Impact

A published dataset containing historical e-commerce order information associated with Canada Goose customers. [2](#source-2)

Documented data types include:

- Purchase history — Order histories, order values, and purchases observed in samples or listed for the HIBP corpus. [1](#source-1) [2](#source-2)
- Names — Customer names observed in samples and listed for the HIBP corpus. [1](#source-1) [2](#source-2)
- Contact information — Email addresses, phone numbers, and billing or shipping addresses observed in samples and listed for the HIBP corpus. [1](#source-1) [2](#source-2)
- Device information — Device and browser information observed in samples and device information listed for the HIBP corpus. [1](#source-1) [2](#source-2)
- IP addresses — IP addresses observed in samples and listed for the HIBP corpus. [1](#source-1) [2](#source-2)
- Payment card information — Partial payment-card fields only: samples included card brand, last four digits, sometimes the first six digits, and authorization metadata; no full card numbers were established. [1](#source-1) [2](#source-2)

A cited record reports 920,000 records (Approximate transaction-record row count described by HIBP, distinct from unique email addresses and affected individuals). [1](#source-1)

A cited record reports 581,877 records (Unique email addresses represented in the HIBP corpus; not a confirmed count of affected people or customers; as of 2026-02-17). [1](#source-1) [2](#source-2)

Canada Goose said it was aware that a historical dataset relating to past customer transactions had been published online. [2](#source-2)

Canada Goose said its review showed no evidence that unmasked financial data was involved. [2](#source-2)

Canada Goose was reviewing the published dataset to assess its accuracy and scope. [2](#source-2)

## Timeline

### July 4, 2025 — Documented activity ended

HIBP BreachDate representing the most recent transaction date in the corpus; not an intrusion date or containment date. [1](#source-1)

### February 15, 2026 — Public disclosure

Date BleepingComputer publicly reported the dataset and Canada Goose's response; not an asserted intrusion or dataset-publication date. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Canada Goose said it had no indication of a incident of its own systems. Samples reviewed by BleepingComputer came from a 1.67 GB dataset released in JSON format and contained detailed e-commerce order records. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/canada-goose-historical-customer-dataset-publication-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Canada Goose breach record

advisory · Have I Been Pwned · Feb 17, 2026

<https://haveibeenpwned.com/api/v3/breach/CanadaGoose>

<a id="source-2"></a>

### Canada Goose investigating as hackers leak 600K customer records

news · BleepingComputer · Feb 15, 2026

<https://www.bleepingcomputer.com/news/security/canada-goose-investigating-as-hackers-leak-600k-customer-records/>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   Canada Goose historical customer-dataset publication: Canada Goose said it was aware that a historical dataset relating to past customer transactions had been published online.
2. **Exposed Data Category · 100% confidence · current**  
   Canada Goose customer-transaction corpus: Purchase history
3. **Exposed Record Count · 90% confidence · current**  
   Canada Goose customer-transaction corpus: 920,000 record
4. **Exposed Record Count · 100% confidence · current**  
   Canada Goose customer-transaction corpus: 581,877 record
5. **Exposed Data Category · 100% confidence · current**  
   Canada Goose customer-transaction corpus: Names
6. **Exposed Data Category · 100% confidence · current**  
   Canada Goose customer-transaction corpus: Contact information
7. **Resulted In · 100% confidence · current**  
   Canada Goose historical customer-dataset publication: Canada Goose said it had no indication of a breach of its own systems.
8. **Ended At · 90% confidence · current**  
   Canada Goose customer-transaction corpus: 2025-07-04
9. **Affected Organization · 100% confidence · current**  
   Canada Goose historical customer-dataset publication: Canada Goose
10. **Resulted In · 100% confidence · current**  
   Canada Goose historical customer-dataset publication: Canada Goose customer-transaction corpus
11. **Exposed Data Category · 100% confidence · current**  
   Canada Goose customer-transaction corpus: Device information
12. **Disclosed At · 100% confidence · current**  
   Canada Goose historical customer-dataset publication: 2026-02-15
13. **Exposed Data Category · 100% confidence · current**  
   Canada Goose customer-transaction corpus: IP addresses
14. **Resulted In · 100% confidence · current**  
   Canada Goose customer-transaction corpus: Samples reviewed by BleepingComputer came from a 1.67 GB dataset released in JSON format and contained detailed e-commerce order records.
15. **Resulted In · 100% confidence · current**  
   Canada Goose historical customer-dataset publication: Canada Goose said its review showed no evidence that unmasked financial data was involved.
16. **Exposed Data Category · 95% confidence · current**  
   Canada Goose customer-transaction corpus: Payment card information
17. **Resulted In · 100% confidence · current**  
   Canada Goose historical customer-dataset publication: Canada Goose was reviewing the published dataset to assess its accuracy and scope.

</details>
