Desk live·
ForensicPost
Breaches/Retail/File 26-0122

Canada Computers Guest Checkout Captured Payment Card Data for a Month

Payment card data was captured through the guest checkout path on Canada Computers’ website between late December 2025 and January 2026. Guest checkout exists to avoid holding data, and captures it in flight instead.

Constructed geometry · not a chart of case data
TargetCanada Computers
ActorUnattributed
D. Kennedy8 min readConfidence: medium1 source reviewed

Payment card data was compromised through the guest checkout path on the Canada Computers retail website, with a capture window running from around 29 December 2025 to 22 January 2026 and roughly 1,284 customers affected.

The affected count is small. The mechanism is worth a file because it inverts an assumption many organisations rely on.

Not Storing It Does Not Mean Not Having It

Guest checkout is frequently presented as the privacy-preserving option: no account is created, no card is stored, the data passes through and is gone.

That protects against a database being stolen later. It offers nothing against capture in flight. Client-side skimming reads the card as the customer types it, before any storage decision is reached, which means a retailer holding no card data at rest can still disclose every card entered during the window.

Detection Is The Hard Part

A capture window of around 25 days is typical, and the reason is that this class of compromise produces almost no server-side evidence. Nothing unusual is logged, the application behaves correctly, transactions complete, and customers receive their goods.

What detects it is monitoring what the page actually loads in a browser — script integrity checks, content security policy enforcement, and synthetic transactions run from outside. Those are front-end controls, and front-end code is rarely inside a security team’s scope.

How we reported this

Compiled from public reporting, listed below. The specific capture mechanism has not been detailed publicly; the discussion of client-side skimming is general to the pattern and labelled as such. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary