LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Canada Goose Data Breach (2025)

CRITICAL severityConfirmedHow we verify

Canada Goose Data Breach (2025): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 4, 2025

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Canada Goose Data Breach (2025)

Reported July 4, 2025. Approximately 582K people affected.

CRITICAL
Severity
582K
People affected
8
Data types exposed
July 4, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Canada Goose disclosed a data breach affecting 582,000 individuals on 4 July 2025. The exposed information includes device information, email addresses, IP addresses, names, and partial credit card data; anyone who has shopped with the company should verify their account status and monitor for suspicious activity.

Severity & verification
CRITICAL severityConfirmed
Exposes financial data.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Canada Goose Data Breach (2025) breach?
582K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Retail and consumer brands remain frequent targets in a threat landscape where customer transaction records and contact details are routinely sought for resale or fraud. Against that backdrop, a dataset linked to Canada Goose customers was published in early 2026, drawing attention to how third-party systems can expose personal and purchase information even when the brand itself is not the direct point of compromise.

Public reporting indicates the material involves hundreds of thousands of unique email addresses and associated customer details. Canada Goose has stated the data appears tied to past transactions and originated from a third-party incident rather than its own systems. The episode matters because it places real contact, location, and partial payment data into open circulation, creating practical risks for people who shopped with the brand.

Breaking down the breach

According to available reporting, a data breach allegedly containing information relating to Canada Goose customers was published publicly in February 2026. The published material is described as containing 920,000 records with 582,000 unique email addresses. Named data elements include names, phone numbers, IP addresses, physical addresses, device information, purchases, and partial credit card data limited to card type and the last four digits.

Canada Goose advised that the data “appears to relate to past customer transactions” and stated that it originated from a breach at a third party in August 2025. The most recent transaction date reflected in the data is July 2025. The incident was reported on 4 July 2025. No further public detail has been provided on the precise method of compromise at the third party, the full technical scope of the exposure, or any confirmed attribution to a named threat actor. The 582,000 figure refers to unique email addresses within the larger set of records.

How a breach like this happens

Incidents of this type commonly begin when an attacker gains access to a system that stores or processes customer records—often a vendor, payment processor, marketing platform, or other third-party service rather than the brand’s primary infrastructure. Once inside, the attacker may extract databases or files containing transaction histories, contact fields, and limited payment metadata. The material is then packaged and later posted on leak sites or forums, sometimes months after the initial intrusion.

In many cases the victim organisation learns of the exposure only after the data appears publicly or after notification from the third party. Because retailers routinely share or process customer data with external partners for fulfilment, analytics, or payments, a single compromised vendor can surface records that appear to belong to the brand. Public detail on the exact vector used in this case remains limited; the pattern above reflects how such third-party exposures typically unfold rather than confirmed specifics of this incident.

About Canada Goose

Canada Goose is a well-known apparel company specialising in outerwear and related products sold through its own stores, e-commerce channels, and authorised retailers. Like other consumer brands in the premium retail sector, it maintains customer accounts, order histories, shipping addresses, and payment-related information necessary to complete purchases and provide service.

A breach involving such records is consequential because the company holds the kinds of personal and transactional data that can be reused for phishing, account takeover attempts, or identity-related fraud. Even when the compromise occurs at a third party, the brand’s customers are the ones whose details surface, and the organisation must manage notification, support, and reputational impact. The scale—hundreds of thousands of unique email addresses—amplifies the number of people potentially affected.

The information in question

The facts name the following categories as exposed: device information, email addresses, IP addresses, names, partial credit card data, phone numbers, physical addresses, and purchases. Partial credit card data is further described as card type and the last four digits. The published set is reported to contain 920,000 records and 582,000 unique email addresses, with the most recent transaction date listed as July 2025.

Organisations of this kind typically also hold order details, shipping preferences, and account credentials or tokens; however, only the elements listed above are confirmed in the public reporting for this incident. Exact contents beyond those named categories remain unconfirmed, and no full inventory of every field has been released.

What's at stake

For individuals, the combination of name, email, phone number, physical address, and purchase history can enable targeted phishing or social-engineering attempts that reference real past orders. Partial card data (type and last four digits) is insufficient for most direct card fraud but can lend credibility to scams. IP and device information may assist in profiling or further reconnaissance. Physical addresses raise the possibility of unwanted mail or, in rarer cases, physical-world targeting.

For Canada Goose, the stakes include customer trust, the cost of investigation and notification, and any regulatory or contractual obligations arising from a third-party incident that exposed its customer data. Because the company has characterised the source as a third-party breach in August 2025, liability and remediation pathways may involve that vendor as well. No public dollar figures or confirmed secondary fraud statistics have been released for this specific event.

If your data was in this breach

If you have shopped with Canada Goose and are concerned your details may be among the 582,000 unique email addresses, begin by treating any unexpected messages that reference past purchases or request payment or login details with caution. Consider changing passwords on related accounts, enabling multi-factor authentication where available, and monitoring bank or card statements for unusual activity even though only partial card data is reported. You may also wish to place a fraud alert with credit bureaus if you believe your full identity details are at elevated risk.

Readers can run a free exposure scan of their email address to check whether their information has surfaced in known breach data. Stay alert to official communications from Canada Goose or the relevant third party rather than unsolicited offers of help, and report suspected fraud to local authorities or consumer-protection agencies as appropriate.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyCanada Goose security record
65/100
DoxxScan™ · Moderate doxx risk
D- 44Very poor record

2 reported incidents on record.

See Canada Goose’s full breach history →
RelatedMore incidents at Canada Goose

More recent breaches

Pass'Sport Data Breach (2025)December 17, 2025APOIA.se Data Breach (2025)December 16, 2025SoundCloud Data Breach (2025)December 15, 2025Under Armour Data Breach (2025)November 17, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Canada Goose Data Breach (2025) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram