If your data was in a breach, the record count doesn’t tell you what to do. What matters is exactly which fields leaked, because an email and password leaking is a completely different problem from an email and SIN leaking. The first one is fixable in an afternoon. The second can follow you for years. This list breaks down every major Canadian breach by what actually got out, so you can match your response to the data that was exposed.
Key Takeaways
- The largest verified Canadian breach is Canadian Tire (October 2025), with 38,306,562 records including names, dates of birth, physical addresses and partial credit card data.
- Most breaches leak only emails and passwords. Only 47 of the 1,034 breaches in the Have I Been Pwned dataset leaked a national ID, government ID, bank account number or passport number.
- Global services cause more Canadian exposure than Canadian companies. Facebook (509 million), Wattpad (268 million) and Deezer (229 million) all dwarf the Canadian entries.
- If a breach exposed only your email and password, change the password everywhere you used it and turn on two-factor authentication. That’s a one-afternoon fix.
- If the breach exposed identity data like a SIN, credit card number or date of birth paired with your address, you need a different response: credit monitoring, fraud alerts and possibly a call to Service Canada.
This list uses verified breach records from Have I Been Pwned. Figures reflect the dataset as of September 2026. Breach data and record counts can change as new information surfaces.

The September 2026 Update
Two things to know this month. Canada Life, dated April 2026 in the verified dataset, has entered the Canadian list with 237,810 records including names, emails, phone numbers, addresses and support ticket contents. And Canadian Tire, from October 2025, remains the breach to check first: it’s the largest Canadian breach in this dataset and the one whose leaked data is most useful to a fraudster.
Notable Canadian Company Breaches
These are verified breaches of Canadian companies, ordered by how likely a Canadian reader is to be affected and searching for them, not by raw size. Every figure comes from the Have I Been Pwned dataset.
| Company | Records | Date | What leaked |
|---|---|---|---|
| Canadian Tire | 38,306,562 | Oct 2025 | DOB, email, gender, name, partial credit card, password, phone, physical address |
| Bell (2017) | 2,231,256 | May 2017 | Email, IP, job title, location, name, password, phone, spoken languages, survey results, username |
| Canada Goose | 581,877 | Jul 2025 | Device info, email, IP, name, partial credit card, phone, physical address, purchases |
| Canada Life | 237,810 | Apr 2026 | Email, job title, name, phone, physical address, salutation, support tickets |
| Bell (2014) | 20,902 | Feb 2014 | Credit cards, gender, password, username |
Canadian Tire: the one to check first
The Canadian Tire breach of October 2025 exposed 38,306,562 records, making it the largest Canadian breach in this verified dataset. But its size isn’t the reason it leads this list. What matters is the combination: names, dates of birth, physical addresses and partial credit card data leaked together. That bundle is what actually enables fraud. A scammer holding your name, birthday, home address and the last digits of your card can pass the identity checks many companies still rely on, and can write a phishing email that references a real purchase at a real address. If you’ve ever had a Canadian Tire account, treat this one as current, not historical.
Bell appears twice, and the two incidents are different problems. The May 2017 breach exposed 2,231,256 records, mostly contact and account details plus passwords. The smaller February 2014 breach of 20,902 records is arguably nastier per person, because it included credit card numbers alongside usernames and passwords. If you were a Bell customer in either era, the passwords involved are long since burned; the question is whether you ever reused them elsewhere.
Canada Goose, from July 2025, exposed 581,877 records including names, contact details, partial card data and purchase histories. Purchase history is easy to shrug off, but it’s exactly what makes a fake “problem with your order” email convincing.
Canada Life, dated April 2026, exposed 237,810 records. No passwords and no card numbers, but it included support ticket contents along with names, emails, phone numbers and addresses. Support tickets can contain anything a customer typed into them, which makes follow-up scams easy to personalize. Expect targeted phishing rather than direct account takeover from this one.
Breach records from Have I Been Pwned, licensed CC BY 4.0.
Global Breaches That Hit Canadians
Most Canadians who appear in a breach weren’t exposed through a Canadian company at all. They were exposed through global services they signed up for years ago, sometimes ones they’ve forgotten they ever used. These are the verified global breaches most likely to include Canadian accounts.
| Service | Records | Date | What leaked |
|---|---|---|---|
| 509,458,528 | Aug 2019 | DOB, email, employer, gender, location, name, phone | |
| Wattpad | 268,765,495 | Jun 2020 | DOB, email, gender, IP, name, password, socials |
| Deezer | 229,037,936 | Apr 2019 | DOB, email, gender, IP, location, name |
| Zynga | 172,869,660 | Sep 2019 | Email, password, phone, username |
| 164,611,595 | May 2012 | Email, password | |
| Adobe | 152,445,165 | Oct 2013 | Email, password hints, password, username |
| MyFitnessPal | 143,606,147 | Feb 2018 | Email, IP, password, username |
| Canva | 137,272,116 | May 2019 | Email, location, name, password, username |
| MyHeritage | 91,991,358 | Oct 2017 | Email, password |
| Dropbox | 68,648,009 | Jul 2012 | Email, password |
| Chegg | 39,721,127 | Apr 2018 | Email, name, password, phone, address, username |
| SHEIN | 39,086,762 | Jun 2018 | Email, password |
Breach records from Have I Been Pwned, licensed CC BY 4.0.
Notice the pattern down the “what leaked” column: email and password, over and over. LinkedIn, Adobe, Dropbox, MyHeritage, SHEIN. These breaches matter for one reason: password reuse. A password stolen from LinkedIn in 2012 still opens your email account today if you used the same one in both places. The Facebook and Deezer entries are the exceptions worth noting: no passwords, but enough personal detail to make impersonation and phishing easier.
The dates deserve a second look too. Half of this table is a decade or more old, and that doesn’t make it safe history. Stolen credentials get resold, recombined and retried for years, which is why an account you abandoned in 2013 can still cause a login alert in 2026. If you recognize even one of these services from an old signup, it’s worth five minutes to confirm that password isn’t still in use anywhere that matters.
Why This List Isn’t Ranked by Size
A ranking by raw record count would be useless to a Canadian reader. The largest datasets in Have I Been Pwned aren’t company breaches at all; they’re credential-stuffing aggregates, giant compilations of stolen logins scraped from thousands of older incidents. The Synthient collection holds 1.96 billion records and Collection #1 holds 773 million, and nobody has ever searched for “Synthient” after hearing about it on the news. So this list ranks by Canadian relevance and recognition instead: the breaches Canadians actually hear about, ask about, and need to check.
The Number That Actually Matters: 47 of 1,034
Of the 1,034 breaches in the Have I Been Pwned dataset, only 47 leaked a SIN-equivalent national ID, a government ID, a bank account number or a passport number. That’s the single most useful fact on this page. Almost every breach you’ll ever be in is an email-and-password problem: serious, but fixable in an afternoon by changing the password everywhere you used it and turning on two-factor authentication. A small minority leak identity data that can’t be changed, and those call for a different response entirely. Knowing which category you’re in is the whole point of reading a list like this one.
If you know what leaked, we have a specific walkthrough for each case: what to do if it was your password, your SIN, or your card number.
See what your combination actually unlocks
A record count says nothing about your personal risk. Our free data breach risk checker has the exact field sets from Canadian Tire, Bell, Canada Goose and the other breaches on this page preloaded. Pick yours, or tick what your notice listed, and see what that mix lets someone do.
Breaches Canadians Ask About That Aren’t in This Dataset
Four breaches Canadians search for constantly are missing from the tables above: LifeLabs, Desjardins, Indigo and 23andMe. They’re real, and they were significant. They’re absent because Have I Been Pwned only catalogues breaches whose data was confirmed circulating, and the data from these incidents wasn’t confirmed in that corpus. That means there’s no verified record count to cite, and this list doesn’t put numbers on breaches it can’t verify. If you were notified by any of these companies, take the notification seriously; absence from this dataset says something about where the data ended up, not about whether the breach happened.
What To Do If a Company You Use Is On This List
Work through these in order. Most people are done inside an hour.
Check the “what leaked” column for that breach, because it decides everything else. An email-and-password breach is a different fix from a breach that included your date of birth, address and partial card data.
Change the password on that account, and on any other account where you used the same or a similar password. If you’re not sure where you reused it, check your browser’s saved passwords. Chrome, Safari, Edge and Firefox all have a built-in password checkup that flags reused and compromised entries. For a walkthrough, see our guide on what to do when your password is leaked.
Turn on two-factor authentication for your email account above all. Email is the master key to your other accounts, because nearly every “forgot password” button on the internet sends a reset link to your inbox. Whoever controls the inbox can reset passwords on banking, shopping and government portals without ever knowing the original password.
Expect the phishing second wave. Scammers use breach news to send fake “security alert” emails pretending to be the breached company or your bank. Go to sites directly instead of clicking email links, and read our guide on how to tell whether a breach email is real before acting on one.
If anything beyond email and password leaked, pull your credit reports. Both Equifax and TransUnion offer them free in Canada, and reviewing them is how you catch accounts you didn’t open.
Find out which breaches include you. NotchUp Shield checks your email address against the verified dataset free and keeps watching after you close this tab, alerting you when a new breach lands.

Frequently Asked Questions
What is the largest Canadian data breach?
Among verified breaches in the Have I Been Pwned dataset, the largest Canadian breach is Canadian Tire, with 38,306,562 records exposed in October 2025. Larger Canadian incidents may exist, but this is the largest with a verifiable record count in the dataset.
What data leaked in the Canadian Tire breach?
The Canadian Tire breach exposed dates of birth, email addresses, genders, names, partial credit card data (card type, expiry and masked number), passwords (stored as PBKDF2 hashes), phone numbers and physical addresses. Canadian Tire confirmed that the incident didn’t impact bank account information or loyalty program data.
Does being in a data breach mean identity theft?
No. Most breaches leak only emails and passwords, which you fix by changing the password everywhere you used it. Only 47 of the 1,034 breaches in this dataset leaked identity data like a national ID, bank account or passport number. If the breach you’re in is email-and-password only, the fix is a password change and two-factor authentication, not a credit freeze.
Were LifeLabs and Desjardins breaches real?
Yes, both were real and significant Canadian breaches, but their data wasn’t confirmed circulating in the Have I Been Pwned corpus, so there’s no verified record count and this list doesn’t attach figures to them. If you were notified by either company, follow their recommended steps regardless of whether the data appears in this dataset.
What should I do first after a breach?
Find out exactly what data leaked, then change the affected password anywhere you reused it, turn on two-factor authentication for your email, and watch for phishing emails that reference the breach in the following weeks.
How do I check if I’m in a data breach?
NotchUp Shield checks your email address against verified breach datasets for free and monitors for future breaches automatically. You can also check directly at Have I Been Pwned. Both services tell you which breaches your email appeared in and what data was exposed.
Are old breaches still dangerous?
Yes. Breach data from 2012 is still circulating and still being used in credential stuffing attacks today. The LinkedIn breach (2012), Adobe breach (2013) and Dropbox breach (2012) collectively exposed hundreds of millions of credentials that remain in active use by attackers more than a decade later. A reused password never expires from an attacker’s perspective.
What’s the difference between a password breach and an identity breach?
A password breach exposes your login credentials, and the fix is changing the password and turning on two-factor authentication. An identity breach exposes data you can’t change, like your SIN, date of birth or government ID number, and requires credit monitoring, fraud alerts and potentially contacting Service Canada. The “what leaked” column in our tables above tells you which type you’re dealing with.
This article is for informational purposes only and does not constitute professional cybersecurity, legal or financial advice. If you believe you’re the victim of identity theft or fraud, contact the Canadian Anti-Fraud Centre and your local police.
Related Reading
- What to do if your password was leaked
- What to do if your SIN was leaked
- What to do if your credit card number was leaked
- Is that breach notification email real?
- How to get your credit report free in Canada
Knowing a breach happened is not the same as knowing you were in it. You can check your own email address against these breaches and around a thousand others free, with no account, at NotchUp Shield.
Breach records from Have I Been Pwned, licensed CC BY 4.0.





