
Canadian discount retail chain Giant Tiger has admitted to suffering a major breach of customer records after a threat actos claimed that they store up to 2.8GB of data from the retailer’s systems.
On March 4, Giant Tiger said it experienced a data security incident that involved an unauthorised third party infiltrating one of its vendor’s internal networks and obtaining copies of customer data. The company said it was investigating the incident with help from third party cyber security experts to understand the nature and scope of the breach.
Without naming the vendor, Alison Scarlett, a spokesperson for the Ottawa-based discount retailer, said the company uses the vendor’s services to manage its customer communications and engagement.
On March 15, Giant Tiger concluded that the sensitive personal information of its customers was compromised during the data security incident. The affected customers engaged with various company divisions, including those who subscribed to Giant Tiger emails or who created accounts on the company’s website.
GT VIP loyalty plan members, customers who opted for online delivery and in-store pick-ups also had their sensitive personal data compromised, including their names, email addresses, and phone numbers.
Without disclosing the identity of the threat actor behind the data security incident or whether it has received a ransom demand, Giant Tiger assured its customers that it will share more updates about the incident in due course.
Last week, a threat actor using the moniker "ShopifyGUY" claimed responsibility for the data security incident and listed Giant Tiger as a victim on their dark web site. The threat actor claimed that they uploaded the entire Giant Tiger customer database stolen from the company in March.
⚠️DATA LEAK ALERT⚠️Allegedly, notorious threat actor ShopifyGUY, has released the Le Slip Français🇫🇷 database.#Clearnet #DarkWebInformer #DarkWeb#Cyberattack #Cybercrime #Cybersecurity #Infosec #Breaking #France
— Dark Web Informer (@DarkWebInformer) April 13, 2024
Compromised Data: More than 1,500,000+ emails including… pic.twitter.com/AEs2RcOPih
“In March 2024, the Canadian discount store chain Giant Tiger Stores Limited... suffered a data breach that exposed over 2.8 million clients. The breach includes over 2.8 million unique email addresses, names, phone numbers and physical addresses,” reads the hacker’s post.
While the database can be accessed by any forum member, it can be downloaded by spending “8 credits”.
Without commenting on the authenticity of the threat actor’s claims, a Giant Tiger spokesperson told BleepingComputer, “On March 4, 2024, Giant Tiger became aware of security concerns related to a third-party vendor we use to manage customer communications and engagement.
“We determined that contact information belonging to certain Giant Tiger customers was obtained without authorisation. We sent notices to all relevant customers informing them of the situation. No payment` information or passwords were involved.”
On April 12, the entire Giant Tiger leaked database was added to the “Have I Been Pwned?” database. According to the database, at least 2,842,669 customer accounts were compromised in the data breach.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543