
Canadian payment gateway provider Slim CD has disclosed a significant cyberattack that has compromised the personal and financial information of nearly 1.7 million users in the US and Canada. The company first noticed unusual activity on 15 June 2024, but investigations revealed the breach had begun almost a year earlier, on 17 August 2023.
Hackers reportedly had access to Slim CD’s systems for almost 12 months. While the company claims that credit card details were only accessible between 14 and 15 June 2024, the compromised information may include sensitive data such as full names, credit card numbers, expiration dates, and customers’ physical addresses.
Slim CD, which stores credit card details to facilitate online transactions, has assured customers that it has taken steps to strengthen its security measures. In a statement, the company emphasised its commitment to data security, stating it had "implemented additional safeguards" and notified both law enforcement and regulatory authorities about the breach.
However, the company has faced criticism for not offering free identity theft protection services to affected users. Instead, Slim CD advised customers to monitor their financial accounts closely and check their credit reports for any suspicious activity.
"We encourage you to remain vigilant against identity theft by reviewing your account statements and monitoring your free credit reports for errors," the company said in its public statement.
This breach highlights the growing risks faced by payment service providers and underscores the need for robust security measures to protect sensitive user information.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543