Cyber extortion group ShinyHunters is back in the spotlight, claiming to have accessed more than 600,000 Canada Goose customer records. The material reportedly includes personal data as well as payment-related information, raising concerns among consumers and the e-commerce industry.

Canada Goose, the Toronto-based luxury clothing brand with a global presence and nearly 4,000 employees, says there is no indication that its internal systems have been compromised.
Canada Goose's position: "We do not see a breach of our systems"
In a statement to BleepingComputer, the company said it is aware that a data set related to past customer transactions recently appeared online.
See also: ClickFix attack distributes StealC malware to Windows systems
"At this time, we have no indication of a breach of our own systems," Canada Goose noted, adding that it is reviewing the published dataset to assess its accuracy and scope.
The company also maintains that the investigation does not show unmasked financial data exposure, stressing that it remains committed to protecting its customers' information.
The 1.67 GB dataset and order files
ShinyHunters added Canada Goose to its leak site this week, claiming the leak includes over 600,000 customer records.
Samples analyzed show that the 1.67 GB file in JSON format contains detailed data e-commerce order. Among other things, it includes:
- Customer names
- Email addresses
- Contact numbers
- Billing and shipping addresses
- IP addresses
- Purchase history
While full card numbers do not appear to be present, details such as the card name, the last four digits and in some cases the first six (BIN), along with payment authorization metadata are included.
See also: ExpressVPN proves it cares about your data

Why this data is dangerous
Even without full card details, such leaks can be exploited for targeted phishing attacks, social engineering scams , and attempts to defraud high-value customers.
Additionally, the data includes device information, browser, and order values, allowing attackers to create consumer profiles and launch more convincing attacks.
Connecting to SSO attacks and cloud environments
ShinyHunters has recently been linked to a wave of social engineering attacks targeting accounts SSO and cloud infrastructure.
However, the group denied that this particular leak was related to these attacks, claiming that it came from a breach of a third-party payment processor and that the data dates back to August 2025. This claim has not been independently verified.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
At the same time, the structure of the dataset's fields resembles typical checkout exports from e-commerce platforms, which reinforces the possibility of third-party involvement.
See also: Odido Telecom: Hacker stole data from 6.2 million customer accounts
Who are ShinyHunters?
ShinyHunters is considered one of the most prolific extortion groups, known for stealing and leaking huge amounts of personal information from major companies and online services.

It often targets SaaS platforms, e-commerce environments, and cloud infrastructures, and has been accused of using vishing and other social engineering techniques.
The data is used for blackmail, sold on underground forums, or published on leak sites when victims do not comply with demands.
It is not yet known how many Canada Goose customers are directly affected or if there will be an official notification to users. The company is continuing to analyze the dataset, while the incident highlights once again the risks arising from the chain of third-party providers in e-commerce.
Source: www.bleepingcomputer.com
