Canada Goose investigating as hackers leak 600K customer records
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内。首先,我得仔细阅读文章,理解主要内容。 文章主要讲的是ShinyHunters这个数据勒索团伙声称窃取了超过60万的Canada Goose客户记录,包括个人信息和支付数据。Canada Goose回应说,这些数据是过去的交易记录,并没有发现自己的系统被入侵的证据。ShinyHunters称数据来自第三方支付处理器的泄露,但这一点未经证实。 接下来,我需要提取关键点:ShinyHunters窃取了60万加拿大鹅客户的数据,包括个人信息和部分支付信息。加拿大鹅表示没有系统被入侵的证据,并正在审查数据。数据可能来自第三方支付处理器的泄露。 现在,我需要用简洁的语言把这些点整合起来,控制在100字以内。确保不遗漏重要信息,同时保持语句通顺。 最后检查一下字数是否符合要求,并确保内容准确无误。 </think> ShinyHunters声称窃取了60多万加拿大鹅客户的记录,包括个人信息和部分支付数据。加拿大鹅表示未发现自身系统被入侵的证据,并正在审查数据以确认其准确性。该数据集可能源自第三方支付处理器的泄露。 2026-2-16 05:0:21 Author: www.bleepingcomputer.com(查看原文) 阅读量:0 收藏

CANADA GOOSE

ShinyHunters, a well-known data extortion group, claims to have stolen more than 600,000 Canada Goose customer records containing personal and payment-related data.

Canada Goose told BleepingComputer the dataset appears to relate to past customer transactions and that it has not found evidence of a breach of its own systems.

Founded in 1957, Canada Goose is a Toronto-based performance luxury outerwear brand with a global retail footprint and nearly 4,000 employees.

Wiz

Canada Goose sees no evidence of breach

"Canada Goose is aware that a historical dataset relating to past customer transactions has recently been published online," the company told BleepingComputer.

"At this time, we have no indication of any breach of our own systems. We are currently reviewing the newly released dataset to assess its accuracy and scope and will take any further steps as may be appropriate. To be clear, our review shows no evidence that unmasked financial data was involved. Canada Goose remains committed to protecting customer information."

1.67 GB dataset contains detailed order records

ShinyHunters added Canada Goose to its data leak site this week, claiming the archive contains more than 600,000 customer records.

ShinyHunters data leak site with 600K customer records
ShinyHunters data leak site listing Canada Goose and 600K records
(BleepingComputer)

Samples reviewed by BleepingComputer show that the 1.67 GB dataset, released in JSON format, contains detailed e-commerce order records, including customer names, email addresses, phone numbers, billing and shipping addresses, IP addresses, and order histories.

The data also includes partial payment card information such as card brand, the last four digits of card numbers, and in some cases the first six digits (BIN), along with payment authorization metadata.

While the dataset does not appear to contain full payment card numbers, the exposed information could still be used for targeted phishing, social engineering, and fraud.

The records also include purchase history, device and browser information, and order values, potentially allowing attackers to profile high-value customers.

Hackers deny link to recent SSO attacks

ShinyHunters has recently been linked to a wave of social-engineering attacks targeting single sign-on (SSO) accounts and cloud environments.

When asked whether the Canada Goose data was obtained through those intrusions, the group told BleepingComputer the dataset was unrelated, claiming it originated from a third-party payment processor breach and dates back to August 2025.

BleepingComputer has not independently verified the claim.

The dataset's schema (specifically, field names like checkout_id, shipping_lines, cart_tokencancel_reason, etc.), however, closely resembles e-commerce checkout exports commonly associated with hosted storefront and payment processing platforms, which may help explain how the data could have originated from a third-party service provider.

Who is ShinyHunters?

ShinyHunters is a prolific data extortion group known for stealing and leaking large volumes of customer data from major brands and online services.

The group has been linked to numerous high-profile breaches and data theft incidents in recent years, often targeting e-commerce platforms, SaaS services, and cloud environments.

In recent reporting, security researchers have tied the group to vishing and social-engineering campaigns used to gain access to corporate accounts and cloud data.

Stolen data is typically used for extortion, sold on underground forums, or published on the group's leak site when victims refuse to pay.

It is not yet known how many Canada Goose customers may be affected or whether individuals will be notified. The company says it is continuing to review the dataset to determine its accuracy and scope.

tines

The future of IT infrastructure is here

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.


文章来源: https://www.bleepingcomputer.com/news/security/canada-goose-investigating-as-hackers-leak-600k-customer-records/
如有侵权请联系:admin#unsafe.sh