LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Informa Canada Inc. dba Shop FAN EXPO Data Breach Notice (Vermont Attorney General)

CRITICAL severityConfirmedHow we verify

Informa Canada Inc. dba Shop FAN EXPO Data Breach Notice (Vermont Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 5, 2026
Informa Canada Inc. dba Shop FAN EXPO Data Breach Notice (Vermont Attorney General)

Reported June 5, 2026. Approximately 2 people affected.

CRITICAL
Severity
2
People affected
1
Data types exposed
June 5, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Informa Canada Inc. dba Shop FAN EXPO disclosed a data breach on 5 June 2026 after the Vermont Attorney General was notified. Two individuals had financial account codes and credit or debit card information exposed; anyone who may have been affected should review the notice and take appropriate protective steps.

Severity & verification
CRITICAL severityConfirmed
Exposes financial data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
2 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A regulatory filing shows that Informa Canada Inc., doing business as Shop FAN EXPO, notified Vermont residents of a data breach involving a very small number of people. The notice, reported to the Vermont Attorney General on June 05, 2026, states that financial account codes and credit and debit account information were among the data exposed. For anyone who has shopped or registered through FAN EXPO channels, even a limited incident of this kind raises practical questions about payment details and how to reduce follow-on risk.

Public detail is limited to what appears in that notice. Two people are listed as affected. The filing does not describe how the incident occurred, how long unauthorized access lasted, or whether other categories of information were involved. What is confirmed is the exposure of sensitive financial identifiers for those individuals and the formal notice to Vermont authorities.

What happened

Informa Canada Inc. dba Shop FAN EXPO submitted a data breach notice that was reported to the Vermont Attorney General on June 05, 2026. According to the filing, the company notified Vermont residents that a breach had occurred and that the information involved included financial account codes as well as credit and debit account information. The notice identifies two people as affected.

No further operational detail is provided in the available record. The method of intrusion or error, the date range of the incident, systems involved, and any containment steps are undisclosed. There is no public attribution to a named threat group in the facts reported. The confirmed elements remain the organization, the reporting date, the headcount of two affected individuals, and the named financial data types.

How a breach like this happens

Incidents that expose payment-related data often follow familiar patterns, though none of these should be read as a description of this specific case. Attackers may obtain credentials through phishing or reused passwords, exploit unpatched software on e-commerce or registration platforms, or abuse misconfigured access to databases and payment processors. In other cases, an insider error, a compromised vendor, or malware on a point-of-sale or back-office system can lead to the same result.

Once access is gained, financial account codes and card details are high-value targets because they can be used for fraudulent charges or sold. Organizations that run ticket sales, merchandise shops, or event registrations routinely process such data; protecting it depends on segmentation, encryption, monitoring, and strict limits on who and what can reach payment systems. When those controls fail or are bypassed, notices like the one filed in Vermont follow. Without a published forensic summary, it is not possible to say which path applied here.

About Informa Canada Inc. dba Shop FAN EXPO

Informa Canada Inc. operates under the Shop FAN EXPO name in connection with FAN EXPO, a well-known brand of large-scale pop-culture, comic, and entertainment conventions held in major cities. Businesses in this sector typically sell tickets, memberships, merchandise, and related products online and on-site. That activity ordinarily requires collecting names, contact details, payment card or account information, and sometimes order or registration records.

A breach affecting even a handful of customers matters because the data types involved—financial account codes and credit or debit account information—are directly usable for fraud. Event and merchandise retailers sit at the intersection of high transaction volume and consumer trust; any confirmed exposure of payment data can affect both the individuals named and confidence in the brand’s handling of checkout and account systems. The Vermont filing establishes that at least two residents were notified after such information was involved.

What was likely exposed

The notice expressly lists financial account codes and credit and debit account information among the data exposed. Those categories generally cover numbers and related identifiers tied to bank or card accounts used for purchases. The filing does not itemize every field, does not state whether full card numbers, expiration dates, CVVs, or bank routing details were included, and does not confirm exposure of names, addresses, emails, or other personal identifiers beyond what is implied by a notice to affected residents.

Organizations of this type commonly hold customer contact data, order histories, and payment tokens or card data processed through payment gateways. Because the public record only names the financial categories above, any broader inventory remains unconfirmed. Readers should treat only the listed types as established by the notice and assume other elements are unknown unless further disclosure appears.

Why it matters

For the two people identified, exposure of financial account codes and credit or debit account information creates a concrete risk of unauthorized charges, account takeover attempts, or fraudulent applications that reuse those details. Even when the absolute number of affected individuals is small, the sensitivity of payment data means the practical impact on each person can be significant—monitoring statements, disputing charges, and in some cases replacing cards or account numbers.

For the organization, a formal attorney-general notice documents a compliance obligation and can trigger further inquiries, contractual notices to payment partners, and reputational scrutiny from customers who shop or register for FAN EXPO-related events. Limited scale does not eliminate those consequences; it simply narrows the circle of people who must take protective steps. Undisclosed factors—such as whether data was encrypted, exfiltrated, or only accessed—leave residual uncertainty that affected individuals cannot resolve from the public filing alone.

If your data was in this breach

If you believe you may be one of the individuals notified, or if you have used Shop FAN EXPO payment channels and want to be cautious, start with the basics: review recent bank and card statements for unfamiliar charges, enable transaction alerts where available, and consider requesting a new card or account number from your issuer if you received a direct notice. Place fraud alerts with major credit bureaus if you see signs of misuse, and keep records of any communication from the company. Avoid sharing additional personal or financial details in response to unsolicited messages that claim to be about this incident.

You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets, which can help you prioritize password changes and monitoring on other accounts. Stay alert for phishing that references FAN EXPO or a “data breach refund,” and rely on official channels if you need to confirm whether you were formally notified.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyInforma Canada Inc. dba Shop FAN EXPO security record
60/100
DoxxScan™ · Moderate doxx risk
D+ 56Weak record

1 reported incident on record.

See Informa Canada Inc. dba Shop FAN EXPO’s full breach history →
RelatedMore incidents at Informa Canada Inc. dba Shop FAN EXPO

More recent breaches

Ocean Edge Resort and Golf Club Data Breach Notice (Vermont Attorney General)August 25, 2026Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)August 24, 2026Valley Perinatal Services LLC d/b/a Advanced Women's Care Data Breach Notice (Vermont Attorney General)August 20, 2026Boston Healthcare for the Homeless Program Data Breach Notice (Vermont Attorney General)August 8, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Informa Canada Inc. dba Shop FAN EXPO Data Breach Notice (Vermont Attorney General) →

Source: Vermont Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram