Groupe Nordik breach exposed gift certificate buyers' card data
- Organization
- Groupe Nordik
- Exploit
- Hacking
- Industry
- Hospitality
Groupe Nordik, the Quebec based operator of the Nordik Spa Nature and Thermea Spa Village brands, told customers in early April 2023 that its online gift certificate platform had been compromised. The company notified affected clients by email on April 5 and confirmed the breach publicly days later.
According to the notice, anyone who bought a gift certificate through the platform between November 4, 2022 and February 27, 2023 may have had their information taken. The exposed fields included full names, street addresses, phone numbers and credit card details. Groupe Nordik said it had noticed a pattern of suspicious activity tied to the gift certificate system in late February and shut the system down to investigate.
Customers reported real financial consequences. CP24 spoke with an Ottawa purchaser, Esha Harish, who found several fraudulent DoorDash charges of more than $100 on the card she had used to buy a Christmas gift certificate. Others described unauthorised Uber and food delivery charges totalling hundreds of dollars, and complaints accumulated on the company's public review pages.
Groupe Nordik said it had enhanced security measures across its systems and would continue working with an outside cybersecurity firm to protect client data. The company did not offer credit monitoring, refunds or other compensation, a point several affected customers criticised. Groupe Nordik operates locations in Chelsea, Quebec, in Winnipeg and in Whitby, Ontario.