Giant Tiger became aware on 4 March 2024 of a security problem at a third-party vendor it used for customer communications, and determined that customer contact information had been taken without authorisation. Records covering around 2.8 million customers were subsequently published in full on a criminal forum.
Reported fields are names, email addresses, physical addresses and telephone numbers. No payment data was reported as involved.
Published, Not Sold
The distinction matters. Data offered for sale reaches whoever pays; data posted free reaches everyone, permanently, and is immediately folded into the aggregate collections that feed later fraud.
Once a set is published there is no recall and no meaningful remedy. Notification tells people what happened; it does not change what is in circulation.
A Retailer’s Marketing Vendor Is A Customer List
The compromised party handled customer communications, which means it held the retailer’s customer list by definition. That is the exposure, and it is invisible on the retailer’s own security assessment.
We keep recording the same question going unasked in supplier reviews: not whether the vendor can be disrupted, but what of yours it is holding while it operates normally.
Compiled from the company’s statements and public reporting, listed below. The 2.8 million figure comes from the published dataset rather than from the company. The vendor has not been named. Corrections: corrections@forensicpost.com.