In mid-February 2026, the threat group ShinyHunters added Canada Goose to its leak site, publishing approximately 600,000 customer records in a 1.67 GB dataset. The Toronto-based luxury outerwear brand confirmed it was investigating but stated it had found no evidence of a breach of its own systems—a strong indicator that the data originated from a third-party payment processor, e-commerce platform, or order management system.
What was leaked
The dataset, published in JSON format, contained e-commerce order records with the following fields:
- PII: Full names, email addresses, phone numbers
- Addresses: Billing and shipping addresses
- Technical metadata: IP addresses, device/browser information
- Transaction data: Order histories, purchase values, order timestamps
- Partial payment card data: Card brand (Visa, Mastercard, etc.), last four digits, and in some cases the first six digits (BIN—Bank Identification Number)
Full payment card numbers were not included, which aligns with PCI compliance: merchants and processors typically store only truncated card data. The presence of BIN and last-four digits, however, suggests the data came from a system that processes or logs payment metadata—typically a payment gateway, order management platform, or analytics pipeline.
Technical analysis: Where did the data come from?
Canada Goose's statement that it found no breach of its own infrastructure narrows the attack surface to third-party systems. E-commerce flows typically involve:
- Checkout flow — Customer data passes through a payment processor (e.g., Stripe, Adyen, Checkout.com) or a headless commerce platform.
- Order management — Order records are stored in an ERP, OMS, or CRM that may aggregate PII and partial card data for fraud detection or analytics.
- Marketing/analytics — Third-party tools (e.g., AppsFlyer, Segment) receive order events with hashed or partial identifiers.
ShinyHunters has a documented history of targeting payment processors and cloud storage. In early 2026, the group breached Checkout.com's legacy cloud storage, demonstrating capability to access payment-adjacent infrastructure. The Canada Goose dataset structure—order-level records with BIN and last-four—is consistent with data exported from a payment gateway, order database, or analytics warehouse rather than a direct compromise of Canada Goose's web application.
Why BIN and last-four matter
Although full card numbers were not exposed, BIN (first 6 digits) + last 4 digits can still enable:
- Card testing — Attackers use the BIN to identify card type and issuer, then test stolen or generated numbers against the last-four to validate cards.
- Targeted phishing — Emails claiming "Your card ending in 1234 was used fraudulently" are more convincing when the attacker knows the actual last-four.
- Account takeover — Combined with name, email, and address, partial card data can help bypass bank or merchant identity checks.
For a luxury brand with high-value transactions, this combination increases the risk of card-not-present fraud and sophisticated social engineering.
ShinyHunters: Tactics and context
ShinyHunters is a prolific data extortion group known for:
- Exploiting OAuth misconfigurations, stolen credentials, and cloud storage exposure
- Publishing data on leak sites when ransoms are refused
- Targeting Okta SSO, marketing analytics platforms (e.g., AppsFlyer), and payment-adjacent systems
In 2026 alone, ShinyHunters has been linked to breaches at Match Group (Tinder, Hinge), Panera Bread, Figure Technologies, and payment processor Checkout.com. The Canada Goose incident fits the pattern of supply-chain or third-party compromise rather than a direct attack on the merchant.
Recommendations for affected customers
- Monitor for phishing — Expect emails or calls referencing Canada Goose orders, card details, or shipping. Verify any links or requests via the official Canada Goose website.
- Enable transaction alerts — Set up real-time notifications from your card issuer for any charges.
- Consider a credit freeze — If you are concerned about identity fraud, place a freeze on your credit file.
- Use unique passwords — If you reused your Canada Goose password elsewhere, change it and enable MFA.
Bottom line
The Canada Goose leak highlights the third-party risk inherent in modern e-commerce: even when a brand's own systems are secure, customer data flows through payment processors, order platforms, and analytics tools—each a potential attack surface. For full breach details, records affected, and timeline, see Canada Goose 2026 breach on BreachHistory.