Toys “R” Us Canada said a cybersecurity incident may have exposed customers’ names, postal addresses, email addresses and phone numbers. The company said passwords and credit-card details were not exposed. It reported discovering the incident on July 30, 2025, and notified customers on October 23, 2025. The number of people affected and the technical cause have not been publicly established in the reports cited below.
Was Toys “R” Us Canada hacked?
The retailer said it learned on July 30, 2025 that information allegedly stolen from its database had appeared on the unindexed internet. It hired cybersecurity experts to contain and investigate the incident, according to Global News and The Canadian Press. Customers were notified on October 23, 2025.
The public reporting does not identify who was responsible or explain how the information was accessed. It also does not give a verified count of affected customers.
What information did the breach expose?
The reported information was customers’ names, postal addresses, email addresses and phone numbers. Toys “R” Us Canada said “no passwords, credit card details or similar confidential data” were exposed, as quoted by Global News.
#1 Best Overall
The retailer’s privacy policy describes other kinds of information it may collect, including payment and delivery information, loyalty and registry data, and account and transaction details. That general description does not establish that those categories were involved in this incident.
Did Toys “R” Us Canada lose my credit-card details?
The company’s statement says credit-card details were not exposed. The available reports do not establish that payment-card information was taken in this incident, so do not treat the broader list of information in the privacy policy as evidence that it was.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
What should I do if I received a breach email?
- Read the notice carefully. The Office of the Privacy Commissioner of Canada advises people to read a breach notice carefully and take protective steps when the breach could create a real risk of significant harm. Check the original Toys “R” Us communication to see whether it says your information was affected. See the commissioner’s breach guidance.
- Be alert for phishing. An exposed email address or phone number can make unexpected messages seem more convincing. Do not click suspicious links or provide passwords or payment details in response to unsolicited email.
- Contact the retailer through a channel you find independently. If the message is unclear, use the contact details on the official Toys “R” Us Canada site rather than replying to an unexpected email or using a link in it.
- Review your accounts and statements. Look for unusual activity, particularly if a message claims to be about your account. The company said passwords and credit-card details were not involved, so the published information does not establish that you need to replace a card or change a password solely because of this incident.
How do I contact Toys “R” Us Canada about my personal information?
Use the retailer’s privacy-rights page to request access to your personal information, ask for a correction or request deletion. Toys “R” Us Canada says it will respond within 30 days or as otherwise permitted by law.
If you believe your privacy concern has not been addressed, the page identifies the Office of the Privacy Commissioner of Canada and, for Quebec, the Commission d’accès à l’information as complaint channels. The appropriate regulator can depend on where you live and the nature of the complaint.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesQuick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
Rank #3
What is still unknown about the incident?
- The number of affected customers has not been publicly established in the cited reports.
- The reports do not identify the attacker, the technical vulnerability or the method used to access information.
- The cited reporting does not establish a ransom demand, regulator finding, settlement or company-funded monitoring service.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




