Giant Tiger customer contact data exposed in third-party vendor breach
- Organization
- Giant Tiger Stores Limited
- Exploit
- Third-Party Data Breach
- Industry
- Retail
Canadian discount chain Giant Tiger began emailing customers in late March 2024 to say that contact information held by one of its vendors had been compromised.
The Ottawa based retailer, which operates more than 260 stores, said it learned of a possible security incident at the third-party provider on March 4, 2024 and concluded on March 15 that customer information was involved. The vendor, which Giant Tiger declined to name, managed customer communications and engagement on the company's behalf. The retailer said its own store systems were not affected.
Which fields were exposed varied by how each person had dealt with the retailer. Newsletter subscribers and website account holders could have had names and email addresses taken, while GT VIP loyalty members and customers who collected online orders in store could also have had phone numbers taken. Home addresses were involved only for customers who ordered products for home delivery. Giant Tiger said no payment information or passwords were affected and that it had no evidence the data had been misused.
The company notified privacy commissioners, contacted affected customers directly, told them to be cautious about unexpected emails and calls, and offered to delete customer records on request. In mid April 2024, after the initial disclosure, a user of a criminal forum posted a dataset said to hold about 2.8 million Giant Tiger customer records containing email addresses, names, phone numbers and physical addresses.