[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvyvmaz6wbh1z":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":13,"affectedCountUnit":23,"hasEnglishDescription":4,"contentLocale":24,"availableLocales":25,"translations":27,"severity":30,"dataClasses":31,"description":40,"seoTitle":41,"seoDescription":42,"logoUrl":43,"isVerified":4,"isSensitive":4,"isSpamList":44,"isMalware":44,"company":45},"6a452308a20f867c8ba8e742","Canadian Tire","Canadian Tire Data Breach","canadian-tire","canadiantire.ca","2025-10-02T00:00:00.000Z","2026-02-25T06:53:25.000Z",null,"2026-07-03T09:38:58.710Z","2026-07-19T00:02:54.816Z","Retail customer account data breach","https:\u002F\u002Fcorp.canadiantire.ca\u002FEnglish\u002FCyber-Incident\u002Fdefault.aspx",[17,19,20],"https:\u002F\u002Fwww.montechnicien.com\u002Fen\u002Fcanadian-tire-in-crisis-42-million-accounts-exposed\u002F","https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fcanadian-tire-2025",38306562,"known","unknown","en",[24,26],"tr",{"en":28,"tr":29},{"slug":9},{"slug":9},"Critical",[32,33,34,35,36,37,38,39],"Dates of birth","Email addresses","Genders","Names","Partial credit card data","Passwords","Phone numbers","Physical addresses","\u003Cp>The Canadian Tire data breach is a large-scale incident on October 2, 2025, affecting the customer records of the Canada-based retail group. The verified searchable scope of this record is 38,306,562 unique email addresses. It has been confirmed that the dataset contains approximately 42 million records, including names, phone numbers, physical addresses, passwords, and in some records, birth dates along with partial credit card information.\u003C\u002Fp>\n\u003Cp>Passwords are not stored in plain text but in PBKDF2 hash form. Partial credit card data refers to limited fields such as card type, expiration date, and masked card number; it does not mean the full card number or security code. Canadian Tire has stated that bank account information and loyalty program data were not affected. Nevertheless, due to the context of password, address, phone number, date of birth, and partial card, the record carries a sensitive data risk.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Verified data types are birth dates, email addresses, gender information, names, partial credit card data, passwords, phone numbers, and physical addresses. It should not be assumed that all of these fields are present in every record; birth date and partial card data are reported for the subset. The main scope is very broad customer contact data and PBKDF2 password hashes.\u003C\u002Fp>\n\u003Cp>The PBKDF2 hash form does not mean plain text password; however, the risk continues for weak or reused passwords. Partial card information alone is not sufficient to make a payment, but it can be used as a trust factor in fake customer service, payment verification, or refund messages. Name, phone, and address information also make these messages more convincing.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified event date is October 2, 2025, and the verified scannable scope is 38,306,562 unique email addresses. Approximately 42 million records in the dataset do not directly correspond to the same number of unique individuals. The same customer may appear in multiple addresses, transactions, accounts, or communication lines. Therefore, the number of records and the number of unique emails should be kept separate.\u003C\u002Fp>\n\u003Cp>This record does not claim that bank account, loyalty program data, full credit card number, card security code, plaintext password, or government-issued ID has been leaked. The verified scope is limited to customer contact fields, PBKDF2 password hashes, birth date from the subset, and partial card data. The risk is more about account security and targeted retail fraud than direct card payments.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Customers who have opened a Canadian Tire account, shopped online, shared a delivery address, or used the same password across different retail and email accounts may be at risk. Password reuse is one of the most critical risks. If the same password is used for email, shopping, social media, work, or payment-related accounts, those accounts may also be targeted.\u003C\u002Fp>\n\u003Cp>Users whose partial card information and birth date are in the subset should be especially careful against fake payment verification and identity confirmation messages. Fake refund, warranty, delivery, campaign, loyalty points, or payment update messages can be supported with real customer information. The presence of card type, last four digits, address, or phone in the message does not prove that the request is genuine.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users in the matching field must ensure that the password they use on their Canadian Tire account is not reused on any other account. If the same or a similar password has been used on other services, the passwords for those accounts must be made unique. Email accounts, shopping accounts, and payment-linked services should be checked first. Two-factor authentication should be enabled on accounts where possible.\u003C\u002Fp>\n\u003Cp>Users should keep card provider notifications enabled and check unexpected payment verification, refund, delivery, or address update messages through official channels. Messages requesting the full card number, security code, bank information, verification code, or account password should not be responded to. Even a message containing partial card information may indicate that the attacker is using a data set.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Large retail data sets create long-term risk when they include password hashes and partial payment context. Users should use a unique password for each retail account, prefer a password manager, and regularly close old shopping accounts. Registered addresses and payment methods should be regularly reviewed.\u003C\u002Fp>\n\u003Cp>For institutions, storing password hashes with strong methods alone is not sufficient; customer communication, addresses, and partial card fields can also be used for fraud. Data retention periods should be reduced, unnecessary partial card fields should be limited, and banking, loyalty, and card coverage should be clearly distinguished in customer notifications. On the user side, card notifications, unique passwords, and the habit of initiating transactions through official channels provide lasting protection.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Seeing a match with the email address in this record indicates that the address is included in the Canadian Tire customer data set. A match does not mean that bank account, loyalty program data, full card number, or plaintext password has been leaked. The user should first determine which account and password they used with this email address and where else the same password has been reused.\u003C\u002Fp>\n\u003Cp>The correct action is to change reused passwords, secure the email account, monitor card notifications, verify delivery and return messages through official channels, and approach messages containing partial card information with caution. This record should be prioritized in terms of account security and retail fraud due to its large scale, password hashes, and partial card data.\u003C\u002Fp>","Canadian Tire Data Breach (38.3 Million Reported Records)","Canadian Tire Data Breach. 38.3 Million reported records are reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fcanadiantire_ca.webp",false,{"name":7,"sector":46,"country":47,"website":10,"websiteArchiveUrl":48,"websiteStatus":48,"websiteCheckedAt":13},"Retail","Canada",""]