Breach report · Retail

Loblaw Data Breach Exposes Customer Contact Information

Loblaw confirmed unauthorized network access exposed customer names, emails and phone numbers, though passwords and payment data were not affected.

Canadian retail giant Loblaw has confirmed that a criminal third party gained unauthorized access to a portion of its IT network, exposing basic customer contact information.

The company stated that suspicious activity was detected within a controlled, non-critical segment of its systems, prompting an internal investigation supported by external cybersecurity experts.

What Information Was Exposed?

According to Loblaw, the breach involved limited customer data, including:

  • Names
  • Email addresses
  • Phone numbers

The company emphasized that the following were not compromised:

  • Passwords
  • Credit card information
  • Health-related data
  • PC Financial systems

Loblaw also confirmed that its financial services subsidiary, PC Financial, was not impacted.

Company Response

Following discovery of the incident:

  • Affected customers were notified directly
  • Impacted digital accounts were automatically logged out
  • Customers must re-authenticate to regain access
  • External cybersecurity experts were engaged to investigate

A company spokesperson stated that “protecting customer data remains a top priority” and that additional security measures are being implemented to strengthen defenses.

Market Impact

While Loblaw recently reported weaker-than-expected quarterly revenue due to inflation and consumer spending pressures, the company indicated that this incident is not expected to materially affect financial performance.

However, reputational risk remains a factor, as retail breaches can impact consumer trust.

Why This Matters

Even when limited to “basic” data, breaches of this type carry real risk.

Exposed contact details can be used for:

  • Targeted phishing campaigns
  • Social engineering attacks
  • Credential stuffing attempts
  • SMS-based scams

Security experts consistently warn that datasets containing verified names, emails, and phone numbers are highly valuable for follow-on fraud activity.

The Bigger Retail Trend

Retail organizations continue to be frequent targets due to:

  • Large customer databases
  • High digital transaction volume
  • Expansive e-commerce infrastructure
  • Complex third-party integrations

Incidents like this reinforce the importance of:

  • Segmented network architecture
  • Continuous monitoring
  • Strong identity controls
  • Rapid customer notification processes

More from the feed

Other incidents we've written up.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.