ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
Reported by BleepingComputer.
Dataset reportedly includes:
β’ checkout_id, cart_token schema indicators
β’ Shipping lines & order values
β’ IP telemetry
β’ Device/browser metadata
β’ Partial PAN (BIN + last four)
β’ Authorization metadata
No full card numbers observed in samples.
Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
Security implications:
β’ BIN + last four enable targeted card fraud attempts
β’ Order value profiling identifies high-value targets
β’ IP/device metadata aids social engineering
β’ Historical datasets still carry active fraud potential
Is vendor risk management keeping pace with SaaS-based commerce stacks?
Source: https://www.bleepingcomputer.com/news/security/canada-goose-investigating-as-hackers-leak-600k-customer-records/
Engage below.
Follow @technadu for advanced threat analysis.
#ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering