Desk live·
ForensicPost
Breaches/Third party/File 24-0314

Giant Tiger Vendor Breach Put 2.8 Million Customer Records Online

The Canadian discount chain learned on 4 March 2024 that a third-party vendor had been compromised. The contact details of 2.8 million customers were later published in full on a criminal forum.

Constructed geometry · not a chart of case data
JurisdictionCanadaOttawathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetGiant Tiger
ActorUnattributed
S. Rosler8 min readConfidence: high2 sources reviewed

Giant Tiger became aware on 4 March 2024 of a security problem at a third-party vendor it used for customer communications, and determined that customer contact information had been taken without authorisation. Records covering around 2.8 million customers were subsequently published in full on a criminal forum.

Reported fields are names, email addresses, physical addresses and telephone numbers. No payment data was reported as involved.

Published, Not Sold

The distinction matters. Data offered for sale reaches whoever pays; data posted free reaches everyone, permanently, and is immediately folded into the aggregate collections that feed later fraud.

Once a set is published there is no recall and no meaningful remedy. Notification tells people what happened; it does not change what is in circulation.

A Retailer’s Marketing Vendor Is A Customer List

The compromised party handled customer communications, which means it held the retailer’s customer list by definition. That is the exposure, and it is invisible on the retailer’s own security assessment.

We keep recording the same question going unasked in supplier reviews: not whether the vendor can be disrupted, but what of yours it is holding while it operates normally.

How we reported this

Compiled from the company’s statements and public reporting, listed below. The 2.8 million figure comes from the published dataset rather than from the company. The vendor has not been named. Corrections: corrections@forensicpost.com.

Sources
  1. Hacker claims Giant Tiger data breach, leaks 2.8M records onlineBleepingComputer
  2. Giant Tiger breach sees 2.8 million records leakedMalwarebytes
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary