← Blog

Loblaw Breach 2026: Forced Logout, Contact Data, What We Know

Share on X

In March 2026, Loblaw Companies—Canada’s largest food and pharmacy retailer, operating Loblaws, Real Canadian Superstore, No Frills, and the PC Optimum loyalty program—disclosed a cybersecurity incident after detecting suspicious activity on a non-critical segment of its IT network.

What was exposed

According to the company’s public statements and press coverage, the incident involved basic customer contact information: names, phone numbers, and email addresses. Loblaw said passwords, health data, credit card information, and PC Financial accounts were not compromised in this event.

Response

Loblaw automatically logged out customers across digital services and required sign-in to access PC Optimum and related apps—an operational step intended to invalidate sessions and reduce risk while the investigation continued.

Why it still matters

Even “low”-sensitivity contact data fuels phishing, SIM swap reconnaissance, and targeted fraud. Customers should treat any email or SMS claiming to be from Loblaw or PC Optimum with normal caution: use official apps or typed URLs, not links in unexpected messages.

Full record on BreachHistory

Timeline, references, and structured fields: Loblaw 2026 breach on BreachHistory.

Sources: BleepingComputer, CP24