The extortion group ShinyHunters published a dataset it claims contains more than 600,000 Canada Goose customer records, including names, contact details, addresses, order histories and partial payment card data. Canada Goose has confirmed to Recorded Future News that a "historical dataset relating to past customer transactions has recently been published online," but says it has "no indication of any breach of our own systems" and that its review shows "no evidence that unmasked financial data was involved." The record count is consistent across every source at 600,000-plus, but it is the attacker's figure in all of them: no independent breach database count and no company confirmation of the total has been published. The leak lands in the middle of a campaign that has now named dozens of victims, and the dispute over where the data actually came from is the most operationally interesting part of the story.
What Happened
ShinyHunters claimed the theft on a Saturday afternoon, per The Record, listing Canada Goose alongside a long run of high-profile victims stretching back to early 2025. The published file is described by secondary coverage (automatedfeeders.com, aqlibrary.com) as a 1.67 GB JSON dataset of order records. Those two sources are lower-tier aggregators and their technical description of the archive has not been independently verified by established security press or by the company.
Canada Goose's public position, given directly to Recorded Future News and repeated in the aggregator coverage as a statement to BleepingComputer, is narrow but specific: the data relates to past customer transactions, there is no indication its own systems were breached, and a review of accuracy and scope is ongoing. The company has not said where it believes the data originated.
ShinyHunters has reportedly offered its own attribution. aqlibrary.com reports the group claims the data came from a third-party payment processor breach dating back to August 2025 rather than from Canada Goose infrastructure. That claim appears in a single OTHER-tier source, is explicitly flagged there as unverified, and should be treated as an actor assertion rather than established fact. Separately, a LinkedIn analysis by a GRC practitioner references an April 2026 supply chain breach that exposed data from Lacoste, Ralph Lauren, Canada Goose and Carter's, which would suggest a different upstream origin. These accounts do not agree, and none of them is confirmed. What can be said plainly is that a large Canada Goose customer dataset is public, the company denies its own systems were the source, and the actual point of compromise remains unestablished.
What Was Taken
Per the secondary coverage, the dataset reportedly contains:
- Customer names, email addresses and phone numbers
- Billing and shipping addresses
- IP addresses, plus device and browser information
- Full order histories and order values
- Partial payment card data: card brand, last four digits, and in some records the first six digits (the BIN), along with payment authorization metadata
Full card numbers do not appear to be present, which is consistent with Canada Goose's statement that no unmasked financial data was involved. That is a meaningful limit on the damage, but it is not the same as low risk. A record that ties a verified name, home address, phone number, card brand, BIN and last four to a specific high-value purchase is close to an ideal script for a convincing fraud call. For a luxury outerwear brand with a customer base skewed toward affluent buyers, the order-value field effectively pre-sorts targets by wealth.
The broader campaign context sharpens this. persprotect.com, tracking the same "pay or leak" operation, counts 33 companies with records published and roughly 72 million email addresses across the indexed sets, and characterizes the exposure as identity rather than credentials: the risk is somebody contacting you with enough real detail to be believed.
Why It Matters
Three things make this brief worth your attention beyond the headline number.
First, the attribution gap is the story. If Canada Goose is right that its systems were not breached, then a Canada Goose-branded consumer harm event originated somewhere in its vendor chain, and the company is absorbing the reputational cost of a compromise it may not have been able to see. The LinkedIn analysis makes the governance point directly: across the 2025 to 2026 retail wave, "none of the perpetrators broke through a firewall," and attackers instead used the relationships between companies and their vendors, contractors and partners. That source also cites Verizon's 2026 DBIR as reporting retail breaches up 2x year over year, though we have not verified that figure against the DBIR itself.
Second, denial and exposure are not mutually exclusive. "No breach of our systems" can be entirely truthful and still leave 600,000 customers exposed. Defenders and comms teams should stop treating perimeter attribution as an all-clear.
Third, the tempo. RingCentral disclosed on July 28 after a "sophisticated social engineering campaign," with Have I Been Pwned later confirming 1.6 million affected accounts against ShinyHunters' claim of 623 GB stolen and 280 GB leaked. Brinks Home identified an intrusion on July 20, with the group claiming 4.9 million Salesforce records. Canada Goose follows weeks later. This is one continuous operation, not isolated events.
The Attack Technique
No confirmed intrusion vector exists for the Canada Goose data specifically. What is well documented is the group's current tradecraft, and it is consistent enough to plan against.
Microsoft's July 13, 2026 research describes campaigns observed between mid-2025 and mid-2026 using tradecraft overlapping with ShinyHunters against SaaS applications, particularly Salesforce. Microsoft identified two primary intrusion paths: vishing aimed at getting a user to approve a malicious OAuth consent, and supply chain compromise through trusted workflows and integrations such as Salesloft and Gainsight. Both routes inherit legitimate user and application privileges, which lets the actor enumerate and query CRM records at scale while evading conventional authentication detections and maintaining persistence. Microsoft is explicit that this was not a Salesforce vulnerability; it was abuse of trusted OAuth relationships. Affected tenants spanned retail, education and manufacturing.
Reporting corroborates this pattern. BleepingComputer reports ShinyHunters told it directly that Brinks Home was breached on July 13 via a Microsoft Entra vishing attack, calling an employee and walking them through an authentication or registration flow that handed over account access, then exfiltrating over 1.1 million rows from the Salesforce Contacts object plus 4,000-plus employee PII rows. Google's incident responders, cited by The Record, noted in January an expansion of ShinyHunters activity involving sophisticated vishing and victim-branded credential harvesting sites to capture SSO credentials and MFA codes.
If the Canada Goose data did come from a processor or vendor rather than the retailer, this is the shape that compromise most plausibly took.
What Organizations Should Do
- Inventory and prune OAuth-connected applications. Microsoft's central recommendation is monitoring OAuth-connected apps and validating third-party integrations. Enumerate every connected app in your SaaS tenants, verify who consented and when, and revoke anything unowned, unused, or over-scoped. Restrict end-user consent so new grants require admin approval.
- Turn on Salesforce event monitoring and the equivalent for every CRM you run. Microsoft worked with Salesforce to improve telemetry granularity for Defender for Cloud Apps, adding near-real-time detection, connected application attribution and expanded permission insight. That telemetry is useless if it is not enabled and ingested.
- Alert on API-driven bulk export, not just logins. These intrusions inherit valid privileges and pass authentication cleanly. The detectable signal is a connected app querying record volumes it has never queried before. Baseline normal per-app query volume and alert on deviation.
- Harden the help desk against vishing. Both the Entra and SSO variants end at a human approving something. Require out-of-band identity verification before any MFA re-registration, password reset, or authentication approval assist. Rehearse it; script it; make refusal the default when verification fails.
- Tier vendors by data sensitivity and hold contractual audit rights. Payment processors and CRM integrators holding full customer order records belong in your top tier, with monitoring, right-to-audit clauses and defined breach-notification SLAs.
- Build an incident response plan for data you did not lose. Canada Goose's situation, a public dataset with no internal breach indication, is now a common scenario. Exercise it with legal, comms and the board, and predetermine how you notify customers when you cannot yet confirm the source.
- For affected consumers: treat any inbound call, email or text referencing a Canada Goose order, refund or settlement as unverified. Callers may quote a real order, a real address, and the last four of a real card. Hang up and call back on a number you already had. Enable two-factor authentication on the email address used for the account.
Sources: Canada Goose Data Breach: 600K Customer Records Leaked by ShinyHunt... | Defending SaaS-based applications against ShinyHunters OAuth abuse... | Canada Goose says leaked customer transaction data did not come fro... | ShinyHunters claims Brinks Home breach, threatens to leak stolen data | RingCentral data breach exposed info of 1.6 million accounts | Canada Goose Data Leak: 600k Customer Records Exposed — What Happen... | Retail Hacks Expose Governance Issues Sanya Arora ... | The ShinyHunters “Pay or Leak” Breaches: Every Company Named (2026)