Canadian Tire e-commerce database incident

Unauthorized activity affected a specific e-commerce database containing customer accounts across four Canadian Tire Corporation retail banners. Customer-account information exposed from the affected e-commerce database.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized activity affected a specific e-commerce database containing customer accounts across four Canadian Tire Corporation retail banners. [1]

Impact

Customer-account information exposed from the affected e-commerce database. [1][2]

Documented data types include:

  • Payment card information — Truncated or masked card information only; Canadian Tire said the incomplete values could not be used for account access, transactions, or purchases. [1][2]
  • Dates of birth — Year of birth was generally present; fewer than 150,000 account records contained full date of birth. [1][2]
  • Names — Names in the affected database and later HIBP corpus. [1][2]
  • Account credentials — Canadian Tire confirmed encrypted passwords; HIBP describes PBKDF2 password hashes. No plaintext-password exposure is asserted. [1][2]
  • Gender information — Gender information listed for the HIBP corpus; not separately confirmed in Canadian Tire’s release. [1][2]
  • Contact information — Addresses and email addresses confirmed by Canadian Tire; HIBP also lists phone numbers for its later corpus. [1][2]

A cited record reports 38,306,562 records (Unique email addresses represented in the later HIBP corpus; not a Canadian Tire-confirmed number of accounts, customers, or affected individuals; as of 2026-02-25). [1]

A cited record reports 150,000 records (Upper-bound representation of Canadian Tire’s statement that fewer than 150,000 account records contained full date of birth; not an exact affected-account count). [1]

The affected database did not include Canadian Tire Bank information or Triangle Rewards loyalty data. [1]

Timeline

  1. Discovery

    Date Canadian Tire Corporation identified and detected the incident; no exact start date is asserted.

    [1]
  2. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Canadian Tire Corporation said it resolved the vulnerability and worked with external experts to enhance related protections. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Canadian Tire Corporation reported no impact on in-store transactions and said all e-commerce systems were operational. Canadian Tire Corporation said it would notify account holders whose records contained more detailed information and offer them credit monitoring. Canadian Tire Corporation reported the matter to applicable privacy regulators. Unauthorized activity was limited to a specific e-commerce database containing customer information. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]