Payment card data was compromised through the guest checkout path on the Canada Computers retail website, with a capture window running from around 29 December 2025 to 22 January 2026 and roughly 1,284 customers affected.
The affected count is small. The mechanism is worth a file because it inverts an assumption many organisations rely on.
Not Storing It Does Not Mean Not Having It
Guest checkout is frequently presented as the privacy-preserving option: no account is created, no card is stored, the data passes through and is gone.
That protects against a database being stolen later. It offers nothing against capture in flight. Client-side skimming reads the card as the customer types it, before any storage decision is reached, which means a retailer holding no card data at rest can still disclose every card entered during the window.
Detection Is The Hard Part
A capture window of around 25 days is typical, and the reason is that this class of compromise produces almost no server-side evidence. Nothing unusual is logged, the application behaves correctly, transactions complete, and customers receive their goods.
What detects it is monitoring what the page actually loads in a browser — script integrity checks, content security policy enforcement, and synthetic transactions run from outside. Those are front-end controls, and front-end code is rarely inside a security team’s scope.
Compiled from public reporting, listed below. The specific capture mechanism has not been detailed publicly; the discussion of client-side skimming is general to the pattern and labelled as such. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense