In March 2026, Loblaw Companies—Canada’s largest food and pharmacy retailer, operating Loblaws, Real Canadian Superstore, No Frills, and the PC Optimum loyalty program—disclosed a cybersecurity incident after detecting suspicious activity on a non-critical segment of its IT network.
What was exposed
According to the company’s public statements and press coverage, the incident involved basic customer contact information: names, phone numbers, and email addresses. Loblaw said passwords, health data, credit card information, and PC Financial accounts were not compromised in this event.
Response
Loblaw automatically logged out customers across digital services and required sign-in to access PC Optimum and related apps—an operational step intended to invalidate sessions and reduce risk while the investigation continued.
Why it still matters
Even “low”-sensitivity contact data fuels phishing, SIM swap reconnaissance, and targeted fraud. Customers should treat any email or SMS claiming to be from Loblaw or PC Optimum with normal caution: use official apps or typed URLs, not links in unexpected messages.
Full record on BreachHistory
Timeline, references, and structured fields: Loblaw 2026 breach on BreachHistory.
Sources: BleepingComputer, CP24