Canadian Tire reports e-commerce data breach
Incident did not impact banking systems, loyalty program, or in-store transactions.
Canadian Tire Corporation (CTC) has disclosed a data breach involving customer information in one of its e-commerce databases.
The company identified the unauthorized activity on October 2, 2025, and has since resolved the vulnerability. All e-commerce systems remain fully operational, and in-store transactions were not affected.
According to the company, the compromised database contained basic personal details for customers with online accounts at Canadian Tire, SportChek, Mark’s/L’Équipeur, and Party City. This included names, addresses, emails, and year of birth. Encrypted passwords and, in some cases, truncated credit card numbers were also exposed; however, these cannot be used for transactions or unauthorized access.
For fewer than 150,000 accounts, the data also included full dates of birth. The breach was contained to the e-commerce database and did not involve Canadian Tire Bank or the company’s Triangle Rewards loyalty program.
In a statement, the company emphasized that data security remains a top priority amid a growing landscape of cyber threats. CTC has identified the affected account holders and will notify them directly in the coming days, offering credit monitoring services. The company has also reported the incident to relevant privacy regulators.
Founded in 1922, Canadian Tire Corporation operates a wide retail network across Canada, including nearly 1,700 retail and gas locations.