Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Giant Tiger said information about some customers was obtained through a security incident involving a third-party vendor in March 2024. The company’s statement listed contact details among the information that could be involved and said passwords and payment information were not included. The widely circulated figure of 2.8 million records is not confirmed by that statement.

What happened in the Giant Tiger incident?

Giant Tiger described a security incident involving a third-party vendor used to manage customer interactions. In a statement reproduced by SooToday, the company said an unauthorized party obtained copies of some customer information on or about March 4, 2024. Giant Tiger said its investigation determined this had happened on March 15.

The statement said Giant Tiger took steps to ensure its own systems remained secure and engaged cybersecurity experts to assist with an independent investigation. It does not describe a compromise of store payment systems.

What information may have been exposed?

The company said the information varied by customer. Its statement identified these possible categories:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Name and email address for email subscribers or people with a GiantTiger.com account.
  • Phone number and street address for other customer categories.

Giant Tiger said passwords and payment information were not involved. The statement does not identify which specific records or categories applied to each person.

Were 2.8 million customers affected?

The 2.8 million figure appears in an April 2024 post on Reddit discussing the leak. It is not given in the company statement reproduced by SooToday, and the sources cited here do not independently verify the number. It should therefore be treated as a reported claim, not a confirmed count of affected customers.

Can you check whether your information was involved?

The reproduced company statement does not provide a lookup tool or another method for an individual to confirm whether their information was among the copies obtained. Because the statement says the data varied by person, the listed categories do not establish that any particular customer was affected.

Giant Tiger’s privacy policy, updated July 24, 2026, describes general information handling and contact routes; it is not an incident-specific status checker or an update to the March 2024 disclosure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should Giant Tiger customers do?

The company said passwords and payment information were not involved, so the incident statement alone does not provide a reason to replace a payment card or reset a Giant Tiger password. Since contact details may have been involved, be cautious with unexpected calls, emails, or texts that claim to be from Giant Tiger or another organization.

  • Do not follow links or provide account, payment, or identity details in an unexpected message. Contact the organization through a channel you locate independently.
  • If a message prompts you to change a password, go to the service’s official site or app directly rather than using the message link.
  • Use extra care with messages that include personal details or create urgency; exposed contact information can make unsolicited messages seem credible.

What Canadian breach-notification rules say

Under section 10.1 of Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), an organization must report a breach to the Privacy Commissioner of Canada and notify affected individuals when it is reasonable to believe the breach creates a real risk of significant harm. Notice must provide enough information for people to understand the breach’s significance and steps they can take to reduce or mitigate harm, and must be given as soon as feasible after the organization determines a breach occurred.

This legal threshold is general context; it does not establish whether a regulator made an incident-specific finding about Giant Tiger or whether the company complied with its duties. The sources cited here do not establish whether a privacy regulator investigated the incident or issued findings.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Canadian breach figures are not Giant Tiger figures

The Office of the Privacy Commissioner of Canada’s 2025–2026 annual report, tabled June 4, 2026, says it received 696 business breach reports affecting 20,328,495 Canadians during that fiscal year. The report also says 42% of Canadian organizations experienced a breach of customer or employee data in the preceding 12 months. These are national statistics, not figures about the Giant Tiger incident. See the OPC annual report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.