---
title: "Canadian Tire e-commerce database incident"
description: "Evidence-backed account of Canadian Tire e-commerce database incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/canadian-tire-ecommerce-database-incident-2025"
markdown_url: "https://www.ally.security/incidents/canadian-tire-ecommerce-database-incident-2025.md"
stix_url: "https://www.ally.security/incidents/canadian-tire-ecommerce-database-incident-2025/stix.json"
---

# Canadian Tire e-commerce database incident

Unauthorized activity affected a specific e-commerce database containing customer accounts across four Canadian Tire Corporation retail banners. Customer-account information exposed from the affected e-commerce database.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized activity affected a specific e-commerce database containing customer accounts across four [Canadian Tire](https://www.canadiantire.ca/) Corporation retail banners. [1](#source-1)

## Impact

Customer-account information exposed from the affected e-commerce database. [1](#source-1) [2](#source-2)

Documented data types include:

- Payment card information — Truncated or masked card information only; Canadian Tire said the incomplete values could not be used for account access, transactions, or purchases. [1](#source-1) [2](#source-2)
- Dates of birth — Year of birth was generally present; fewer than 150,000 account records contained full date of birth. [1](#source-1) [2](#source-2)
- Names — Names in the affected database and later HIBP corpus. [1](#source-1) [2](#source-2)
- Account credentials — Canadian Tire confirmed encrypted passwords; HIBP describes PBKDF2 password hashes. No plaintext-password exposure is asserted. [1](#source-1) [2](#source-2)
- Gender information — Gender information listed for the HIBP corpus; not separately confirmed in Canadian Tire's release. [1](#source-1) [2](#source-2)
- Contact information — Addresses and email addresses confirmed by Canadian Tire; HIBP also lists phone numbers for its later corpus. [1](#source-1) [2](#source-2)

A cited record reports 38,306,562 records (Unique email addresses represented in the later HIBP corpus; not a Canadian Tire-confirmed number of accounts, customers, or affected individuals; as of 2026-02-25). [1](#source-1)

A cited record reports 150,000 records (Upper-bound representation of Canadian Tire's statement that fewer than 150,000 account records contained full date of birth; not an exact affected-account count). [1](#source-1)

The affected database did not include Canadian Tire Bank information or Triangle Rewards loyalty data. [1](#source-1)

## Timeline

### October 2, 2025 — Discovery

Date Canadian Tire Corporation identified and detected the incident; no exact start date is asserted. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Canadian Tire Corporation said it resolved the vulnerability and worked with external experts to enhance related protections. [1](#source-1)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Canadian Tire Corporation reported no impact on in-store transactions and said all e-commerce systems were operational. Canadian Tire Corporation said it would notify account holders whose records contained more detailed information and offer them credit monitoring. Canadian Tire Corporation reported the matter to applicable privacy regulators. Unauthorized activity was limited to a specific e-commerce database containing customer information. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/canadian-tire-ecommerce-database-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Advisory: Canadian Tire Corporation E-Commerce Data Incident

official · Canadian Tire Corporation, Limited

<https://canadiantire.mediaroom.com/2025-10-14-Advisory-Canadian-Tire-Corporation-E-Commerce-Data-Incident>

<a id="source-2"></a>

### Canadian Tire breach record

advisory · Have I Been Pwned · Feb 25, 2026

<https://haveibeenpwned.com/api/v3/breach/CanadianTire>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Exposed Record Count · 100% confidence · current**  
   Canadian Tire e-commerce account data exposure: 38,306,562 record
2. **Affected Organization · 100% confidence · current**  
   October 2025 Canadian Tire e-commerce database breach: SportChek
3. **Resulted In · 100% confidence · current**  
   October 2025 Canadian Tire e-commerce database breach: Canadian Tire Corporation reported no impact on in-store transactions and said all e-commerce systems were operational.
4. **Exposed Data Category · 100% confidence · current**  
   Canadian Tire e-commerce account data exposure: Payment card information
5. **Exposed Data Category · 100% confidence · current**  
   Canadian Tire e-commerce account data exposure: Dates of birth
6. **Discovered At · 100% confidence · current**  
   October 2025 Canadian Tire e-commerce database breach: 2025-10-02
7. **Affected Organization · 100% confidence · current**  
   October 2025 Canadian Tire e-commerce database breach: Party City Canada
8. **Resulted In · 100% confidence · current**  
   October 2025 Canadian Tire e-commerce database breach: Canadian Tire Corporation said it resolved the vulnerability and worked with external experts to enhance related protections.
9. **Exposed Data Category · 100% confidence · current**  
   Canadian Tire e-commerce account data exposure: Names
10. **Resulted In · 100% confidence · current**  
   October 2025 Canadian Tire e-commerce database breach: The affected database did not include Canadian Tire Bank information or Triangle Rewards loyalty data.
11. **Exposed Data Category · 100% confidence · current**  
   Canadian Tire e-commerce account data exposure: Account credentials
12. **Affected Organization · 100% confidence · current**  
   October 2025 Canadian Tire e-commerce database breach: Canadian Tire
13. **Exposed Data Category · 90% confidence · current**  
   Canadian Tire e-commerce account data exposure: Gender information
14. **Resulted In · 100% confidence · current**  
   Canadian Tire customer and regulator notification: Canadian Tire Corporation said it would notify account holders whose records contained more detailed information and offer them credit monitoring.
15. **Resulted In · 100% confidence · current**  
   Canadian Tire customer and regulator notification: Canadian Tire Corporation reported the matter to applicable privacy regulators.
16. **Exposed Data Category · 100% confidence · current**  
   Canadian Tire e-commerce account data exposure: Contact information
17. **Exposed Record Count · 100% confidence · current**  
   Canadian Tire e-commerce account data exposure: 150,000 record
18. **Resulted In · 100% confidence · current**  
   October 2025 Canadian Tire e-commerce database breach: Canadian Tire customer and regulator notification
19. **Affected Organization · 100% confidence · current**  
   October 2025 Canadian Tire e-commerce database breach: Canadian Tire Corporation, Limited
20. **Resulted In · 100% confidence · current**  
   October 2025 Canadian Tire e-commerce database breach: Canadian Tire e-commerce account data exposure
21. **Affected Organization · 100% confidence · current**  
   October 2025 Canadian Tire e-commerce database breach: Mark's
22. **Resulted In · 100% confidence · current**  
   October 2025 Canadian Tire e-commerce database breach: Unauthorized activity was limited to a specific e-commerce database containing customer information.

</details>
