Canadian Tire recently experienced a significant security incident involving an unauthorized intrusion into its e-commerce database during October 2025. This breach exposed the personal information of over 38 million accounts across several brands, including SportChek, Mark’s, and Party City.
The retail giant first identified the unauthorized access on October 2, leading to an investigation into the scope of the leaked data. According to company statements, the affected database contained names, email addresses, and encrypted passwords. While some partial credit card information and dates of birth were present in the set, the company emphasized that the sensitive financial data was incomplete and could not be used to facilitate fraudulent transactions or gain direct account access.
Despite the company's initial disclosures, recent updates from the breach notification service Have I Been Pwned suggest the scale of the incident may be larger than previously understood. The platform reported that approximately 42 million records were involved, including over 38 million unique email addresses. This updated analysis indicates that the exposed data also included physical addresses, phone numbers, and gender information, which provides a more comprehensive picture of the privacy risk to consumers.
Technical details reveal that while passwords were encrypted using PBKDF2 hashing, the sheer volume of contact information makes the affected individuals potential targets for phishing and social engineering. Canadian Tire has maintained that its banking division and Triangle Rewards loyalty program were not impacted by the breach. This distinction is vital for customers who use the company's financial services, as those higher-security databases remained isolated from the compromised e-commerce system.
The company has spent the months following the discovery notifying affected customers via email to advise them on protective measures. While Canadian Tire has cooperated with regulatory authorities and security platforms, it has not yet provided a final, official count of the total number of individuals impacted. Users are encouraged to remain vigilant for suspicious communications and to update their security credentials across all related retail platforms.
Source: Canadian Tire Data Breach Impacts 38 Million Customer Accounts


