← Blog

Golf Canada Breach: HIBP Loads 569K Emails

Share on X

Have I Been Pwned loaded a Golf Canada breach covering about 569,000 unique email addresses after user records allegedly sourced from the national golf body circulated on Telegram in mid-2026. HIBP says Golf Canada did not respond to multiple contact attempts. Canonical row: golf-canada-hibp2026. Primary: HIBP Golf Canada.

If you play, work, or volunteer in Canadian golf, this is the breach notice that arrives months late through a breach directory instead of a branded letter.

What the Golf Canada data breach includes

Per HIBP, the circulating corpus held names, usernames, dates of birth, genders, and approximate geography (city, province, postcode) alongside those ~569k emails. Breach timing is described as mid-2026 (HIBP/Mozilla cite around May 14, 2026 for the underlying event); HIBP published the load in late August 2026.

It remains unclear whether the data came from an exposed website feature or a classic vulnerability. Silence from Golf Canada keeps the root-cause column thin.

What we do not know

No public Golf Canada member letter with an attested census was located at indexing. No password hashes are listed in the HIBP field set for this load. Exact club-membership vs casual-registrant mix is unpublished. Treat the 569k figure as HIBP’s unique-email count, not a Golf Canada press-kit number.

Who is at risk

Anyone who created a Golf Canada online account, registered for events, or otherwise handed the federation an email and profile. Juniors whose parents registered them. Coaches and club admins who reused Golf Canada passwords elsewhere. Provincial association staff who shared the same email into federation tools.

What you should do

  1. Search your address on Have I Been Pwned and confirm the Golf Canada entry.
  2. Change the Golf Canada password if you still have an account; use a unique password.
  3. Watch for phishing that cites your club city or province from the dump.
  4. Enable MFA on email and any golf-retail accounts sharing that address.
  5. Parents: review junior profiles you created years ago.
  6. Ignore Telegram “check if you’re in the Golf Canada leak” bots.
  7. Clubs: brief members that HIBP published this load even without a federation FAQ.
  8. Keep HIBP and BreachHistory links; do not trust random PDF “official notices.”

Canonical record

golf-canada-hibp2026 — 568972 / ~569k unique emails; HIBP-verified corpus; companyConfirmed false pending Golf Canada notice.

Phishing after a named breach almost always arrives before the polished FAQ. Attackers do not wait for your insurer or federation to finish forensics. They need a headline and a few accurate fields.

Reuse of passwords across sports, travel, and health portals remains the fastest path from an email dump to account takeover. Unique passwords plus MFA beat regret.

Journalists should separate confirmed company sentences from actor table counts in every headline. Collapsing them produces false precision.

Regulators measuring notification quality will look at how quickly individuals learn actionable steps — not how quickly a leak site posts screenshots.

If you forward breach news in family chats, forward the official domain and the BreachHistory canonical link, not a screenshot of a forum sales thread.

Secondary scams include fake credit-monitoring signups, fake CNIL or PIPEDA complaint portals, and “leak lookup” apps that harvest more data than they return.

Companies reading this as a peer incident should tabletop: Sunday discovery, same-day regulator notice, member SMS without payment links, and a holding statement that refuses to invent a census.

Data minimization still wins. NIR and IBAN in the same wide analytics table is a gift to whoever lands a SQLi or supplier foothold.

International readers with French or Canadian accounts should not assume “local only.” Diaspora inboxes get the same personalized lures.

BreachHistory updates rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture.

Call-center staff should use out-of-band verification when a caller recites breach trivia. Accuracy is not authentication.

Clubs, brokers, and HR partners often become the weak redistribution channel for stolen contact lists. Brief them early.

Open browser bookmarks to official portals now so you are not searching under panic later.

When samples appear in trade press, demand schema description without republishing identifiable rows.

Expect copycat leak posts that paste the same victim name with inflated numbers. Check dates and primary URLs.

Legal teams drafting class notices should wait for inventory rather than marketing every actor CSV as gospel.

Members who already froze credit or enabled MFA after older breaches still need a fresh look at SEPA mandates and email filters.

The practical closing line: confirm via official channels, rotate reused passwords, and treat hyper-accurate outreach as hostile.

Phishing after a named breach almost always arrives before the polished FAQ. Attackers do not wait for your insurer or federation to finish forensics. They need a headline and a few accurate fields.

Reuse of passwords across sports, travel, and health portals remains the fastest path from an email dump to account takeover. Unique passwords plus MFA beat regret.

Journalists should separate confirmed company sentences from actor table counts in every headline. Collapsing them produces false precision.

Regulators measuring notification quality will look at how quickly individuals learn actionable steps — not how quickly a leak site posts screenshots.

If you forward breach news in family chats, forward the official domain and the BreachHistory canonical link, not a screenshot of a forum sales thread.

Secondary scams include fake credit-monitoring signups, fake CNIL or PIPEDA complaint portals, and “leak lookup” apps that harvest more data than they return.

Companies reading this as a peer incident should tabletop: Sunday discovery, same-day regulator notice, member SMS without payment links, and a holding statement that refuses to invent a census.

Data minimization still wins. NIR and IBAN in the same wide analytics table is a gift to whoever lands a SQLi or supplier foothold.

International readers with French or Canadian accounts should not assume “local only.” Diaspora inboxes get the same personalized lures.

BreachHistory updates rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture.

Call-center staff should use out-of-band verification when a caller recites breach trivia. Accuracy is not authentication.

Clubs, brokers, and HR partners often become the weak redistribution channel for stolen contact lists. Brief them early.

Open browser bookmarks to official portals now so you are not searching under panic later.

When samples appear in trade press, demand schema description without republishing identifiable rows.

Expect copycat leak posts that paste the same victim name with inflated numbers. Check dates and primary URLs.

Legal teams drafting class notices should wait for inventory rather than marketing every actor CSV as gospel.

Members who already froze credit or enabled MFA after older breaches still need a fresh look at SEPA mandates and email filters.

The practical closing line: confirm via official channels, rotate reused passwords, and treat hyper-accurate outreach as hostile.

Phishing after a named breach almost always arrives before the polished FAQ. Attackers do not wait for your insurer or federation to finish forensics. They need a headline and a few accurate fields.

Reuse of passwords across sports, travel, and health portals remains the fastest path from an email dump to account takeover. Unique passwords plus MFA beat regret.

Journalists should separate confirmed company sentences from actor table counts in every headline. Collapsing them produces false precision.

Regulators measuring notification quality will look at how quickly individuals learn actionable steps — not how quickly a leak site posts screenshots.

If you forward breach news in family chats, forward the official domain and the BreachHistory canonical link, not a screenshot of a forum sales thread.

Secondary scams include fake credit-monitoring signups, fake CNIL or PIPEDA complaint portals, and “leak lookup” apps that harvest more data than they return.

Companies reading this as a peer incident should tabletop: Sunday discovery, same-day regulator notice, member SMS without payment links, and a holding statement that refuses to invent a census.

Data minimization still wins. NIR and IBAN in the same wide analytics table is a gift to whoever lands a SQLi or supplier foothold.

International readers with French or Canadian accounts should not assume “local only.” Diaspora inboxes get the same personalized lures.

BreachHistory updates rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture.

Call-center staff should use out-of-band verification when a caller recites breach trivia. Accuracy is not authentication.

Clubs, brokers, and HR partners often become the weak redistribution channel for stolen contact lists. Brief them early.

Open browser bookmarks to official portals now so you are not searching under panic later.

When samples appear in trade press, demand schema description without republishing identifiable rows.

Expect copycat leak posts that paste the same victim name with inflated numbers. Check dates and primary URLs.

Legal teams drafting class notices should wait for inventory rather than marketing every actor CSV as gospel.

Members who already froze credit or enabled MFA after older breaches still need a fresh look at SEPA mandates and email filters.

The practical closing line: confirm via official channels, rotate reused passwords, and treat hyper-accurate outreach as hostile.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.