[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f26iz1spmbn17r":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":13,"affectedCountUnit":23,"hasEnglishDescription":4,"contentLocale":24,"availableLocales":25,"translations":27,"severity":30,"dataClasses":31,"description":40,"seoTitle":41,"seoDescription":42,"logoUrl":43,"isVerified":4,"isSensitive":4,"isSpamList":44,"isMalware":44,"company":45},"6a452308a20f867c8ba8e72e","Canada Goose","Canada Goose Data Breach","canada-goose","canadagoose.com","2025-07-04T00:00:00.000Z","2026-02-17T00:19:51.000Z",null,"2026-07-03T09:39:27.219Z","2026-07-19T00:02:48.143Z","Luxury retail customer transaction data breach","https:\u002F\u002Fwww.canadagoose.com\u002F",[17,19,20],"https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fcanada-goose-2025","https:\u002F\u002Fwww.breachsense.com\u002Fbreaches\u002Fcanada-goose-data-breach\u002F",581877,"known","unknown","en",[24,26],"tr",{"en":28,"tr":29},{"slug":9},{"slug":9},"High",[32,33,34,35,36,37,38,39],"Device information","Email addresses","IP addresses","Names","Partial credit card data","Phone numbers","Physical addresses","Purchases","\u003Cp>The Canada Goose data breach is a retail data incident associated with past customer transaction data and was published in February 2026. The record confirmed a searchable scope of 581,877 unique email addresses. It was reported that the dataset contained a total of approximately 920,000 records, the most recent transaction date was July 2025, and the incident was linked to a third-party source breach.\u003C\u002Fp>\n\u003Cp>The verified data classes are device information, email addresses, IP addresses, names, partial credit card data, phone numbers, physical addresses, and purchase information. Partial credit card data does not mean the full card number or security code; it refers to limited information such as the card type and the last four digits. Nevertheless, due to the context of purchase and partial payment, the record should be handled with the risk of sensitive data.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Verified data types are device information, email addresses, IP addresses, names, partial credit card data, phone numbers, physical addresses, and purchase information. Together, these fields create a limited but fraud-usable profile about the user's past shopping, delivery information, communication channels, and payment card context.\u003C\u002Fp>\n\u003Cp>Partial card data alone is not sufficient to make a payment; however, the card type and the last four digits can be used as a trust factor in fake refund, payment verification, or account security messages. When purchase information is combined with the context of high-value products, it can make fake warranty, product verification, delivery, refund, or special promotion messages more convincing.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified date is July 4, 2025, and the verified searchable scope is 581,877 unique email addresses. The dataset has been reported to contain approximately 920 thousand records; this number is not directly the number of unique individuals. The same customer may appear in multiple transaction, delivery, payment, or address lines. Therefore, the number of records and the number of unique emails should be kept separate.\u003C\u002Fp>\n\u003Cp>This record does not claim that the full credit card number, card security code, bank account, password, account session, or official identification document was leaked. Canada Goose stated that the data appears to be associated with past customer transactions and came from a third-party source. The risk is not so much that direct payment can be made, but that fake messages become more convincing with actual purchase and partial card details.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Customers who have previously shopped through Canada Goose, shared a delivery address and phone number, and have records of using a payment card in transactions may be at risk. It creates a suitable context for high-value retail products, fake warranty, returns, repairs, authenticity checks, or delivery messages. Users should pay special attention to messages that appear consistent with their past purchases.\u003C\u002Fp>\n\u003Cp>A physical address and phone number indicate that the attack can extend beyond email. Fake shipping fees, address corrections, product returns, maintenance, or warranty renewal messages may come via SMS or phone call. IP and device information can also be used in fake security alerts. The presence of the last four digits or the correct address in the message does not prove that the request is real.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users in the matching field should check their Canada Goose account from the known login address and use strong and unique passwords on their shopping accounts with the same email address. Passwords are not a verified data class in this incident; still, attempts may be made to collect passwords through fake login pages. Links in refund, warranty, delivery, or payment verification messages should not be used directly.\u003C\u002Fp>\n\u003Cp>Users should keep card provider notifications enabled and monitor unexpected transaction attempts and card-related verification requests. Messages requesting full card information or security codes should not be responded to. A message containing partial card information may indicate that the attacker is using past transaction data. Delivery and return transactions should only be verified through known official channels.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In high-value retail accounts, the context of purchase, address, and partial payment carries fraud potential for a long time. Users should use unique passwords for shopping accounts, regularly review saved payment methods, and delete unnecessary old addresses. Limited information such as the last four digits of a card should not be accepted alone as proof of security in verification questions.\u003C\u002Fp>\n\u003Cp>From the perspective of institutions, this incident shows that historical transaction data held by third parties also affects customer security. Purchase, delivery, device, and partial card information should be kept according to the principle of minimal data, third-party retention periods should be audited, and full scope should be clearly separated in customer notifications. On the user side, initiating return, warranty, and delivery messages through official channels should be a basic habit.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The presence of a match with the email address in this record indicates that the address is included in the historical customer transaction data set associated with Canada Goose. The match does not imply that the full card number, security code, or password has been leaked. The user should first determine which purchase, delivery, or payment card information was used with this email address.\u003C\u002Fp>\n\u003Cp>The correct action is to secure the shopping account, monitor card notifications, verify delivery and return messages through official channels, approach messages containing the last four digits of the card or address with caution, and not share full payment information through any link. This record carries a risk of targeted fraud, particularly due to high-value retail products and partial card context.\u003C\u002Fp>","Canada Goose Data Breach (581.9 Thousand Reported Records)","Canada Goose Data Breach. 581.9 Thousand reported records are reported. Reported data: Device information, Email addresses, IP addresses. Review the scope…","\u002Fuploads\u002Flogo\u002Fcanadagoose_com.webp",false,{"name":7,"sector":46,"country":47,"website":10,"websiteArchiveUrl":48,"websiteStatus":48,"websiteCheckedAt":13},"Retail","Canada",""]