Last month, Canadian retail chain Giant Tiger revealed a data breach that affected millions of people.

Now, a hacker has publicly claimed responsibility for the data breach and leaked 2.8 million files purportedly belonging to Giant Tiger customers.
Data breach monitoring service HaveIBeenPwned has also added the database to make it easier for users to find out if information has been compromised.
Giant Tiger: 2.8 million customer records leaked online
BleepingComputer spotted a post titled “Giant Tiger Database – Leaked, Download!!” on a hacking forum. The hacker behind the post claims to have uploaded Giant Tiger’s “complete” database of customer records. The files were stolen in March 2024.
See also: Data breach affects 300,000 taxi passengers in UK and Ireland
“In March 2024, Canadian chain Giant Tiger Stores Limited… suffered a data breach that affected over 2.8 million customers,” the attacker states. “The breach includes over 2.8 million unique email addresses, names, phone numbers, and physical addresses.”
Additionally, according to the hacker, the stolen data includes “website activity” of Giant Tiger customers.
“I finally opened 60 out of 60 pages of the database section !”one forum member replied to the post, while others asked to preview a sample of the dataset. The attacker posted a small excerpt.
Essentially, . . customer data has been leaked for freeAlthough the download link must be unlocked with “8 credits,” such credits are usually generated through comments on existing posts or through the creation of new posts
Cybercriminals hack into companies and steal sensitive data to extort money. If a successful extortion attempt fails, attackers may leak the stolen data online or sell it on the dark web.
See also: AT&T: Data breach ultimately affects 51 million customers

Giant Tiger: Breach via third-party supplier
While Giant Tiger has not confirmed the authenticity of the leaked data, a spokesperson told BleepingComputer: “On March 4, 2024, Giant Tiger became aware of some security issues related to a third-party vendor communications and engagement customer. We determined that contact information belonging to certain Giant Tiger customers was obtained without authorization. We sent notifications to all affected customers informing them of the situation. No payment information or passwords were involved .”
HaveIBeenPwned
As of April 12, the exposed data set has been added to “Have I Been Pwned?”, a free online service that allows users to check whether their data was affected in known data breaches.
The number of compromised records related to this incident is 2,842,669, with the service reporting that 46% of these records were already in database .
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Giant Tiger customers should be alert to any suspicious messages or incoming communications claiming to be from the company.
See also: Epilepsy Foundation (EFMNY): Ransomware attack and data breach

Consequences of the data breach
The data breach could have significant implications for Giant Tiger customers . First, their personal information , such as names, addresses, phone numbers, and email addresses, has been leaked , increasing the risk of fraud or identity theft.
Second, data breaches can lead to a loss of trust. Customers may feel that the company cannot protect their personal data and, as a result, decide not to shop with Giant Tiger anymore.
Finally, customers may experience anxiety and stress resulting from the exposure of their personal data. This can have psychological effects, as customers may be concerned about the security of their personal information and the possibility of further attacks.
Source: www.bleepingcomputer.com
