Giant Tiger said customer information was obtained through a security incident involving a third-party vendor in March 2024. Its statement listed contact details among the information that may have been affected and said passwords and payment information were not involved. The headline figure of 2.8 million is reported online, but is not confirmed in the company statement reproduced in local reporting.
What happened in the Giant Tiger breach?
Giant Tiger described a security incident involving a third-party vendor used to manage customer interactions. The company said an unauthorized party obtained copies of some customer information on or about March 4, 2024, and that its investigation determined this had happened on March 15. It also said it took steps to ensure its own systems remained secure and hired cybersecurity experts to assist with an independent investigation. These details come from Giant Tiger’s statement as reproduced by SooToday; they are not an independent forensic account of the incident.
The company’s statement said: “Giant Tiger values the trust and loyalty of our customers above all else, and we want to ensure you are aware of the facts.”
What information may have been exposed?
Giant Tiger said the information involved varied by customer. The categories it identified were:
#1 Best Overall
- Name and email address for email subscribers or people with a GiantTiger.com account.
- Phone number and street address for other customer categories.
The statement said passwords and payment information were not included. It described the incident as involving a third-party customer-interaction vendor; it did not report that store payment systems were compromised.
Were 2.8 million customers affected?
The 2.8 million figure appears in an April 2024 Reddit post about records allegedly leaked online. The company statement reproduced by SooToday does not give an affected-customer count, and the post does not independently establish that number. Treat 2.8 million as a reported figure, not a confirmed total from Giant Tiger.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
How can you tell whether your information was involved?
The statement reproduced in the local report does not provide a way to check an individual’s exposure. Because the information varied by customer, the published categories do not show whether a particular person’s details were among the records obtained. Giant Tiger’s privacy policy, updated July 24, 2026, describes general information handling and contact routes; it is not an incident-specific exposure lookup.
What should you do now?
- Be alert to unexpected messages. If someone contacts you claiming to represent Giant Tiger, a delivery service, or a financial institution, don’t use links or phone numbers in an unsolicited message. Contact the organization through a channel you find independently.
- Assess the information at risk realistically. The company said passwords and payment information were not involved. Its statement therefore does not, by itself, indicate that you need to replace a card or reset a Giant Tiger password because of this incident.
- Use ordinary account security practices. If you reuse a password elsewhere, change it on those other services and use unique passwords going forward. This is a general precaution, not a response the company said was required by this incident.
What Canadian breach-notification rules say
Under section 10.1 of Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), an organization must report a breach to the Privacy Commissioner and notify affected individuals when it is reasonable to believe the breach creates a real risk of significant harm. Notice must contain enough information for people to understand the significance of the breach and steps they can take to reduce or mitigate harm, and must be given as soon as feasible after the organization determines a breach occurred.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #3
That statutory threshold is general context, not evidence of a specific regulatory finding about Giant Tiger. The sources cited here do not establish whether a regulator conducted an incident-specific investigation or issued findings.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Canadian breach reports in context
The Office of the Privacy Commissioner of Canada reported receiving 696 business breach reports affecting 20,328,495 Canadians in fiscal year 2025–2026. Its annual report also said 42% of Canadian organizations had experienced a breach of customer or employee data in the preceding 12 months. These are national statistics from the 2025–2026 annual report, tabled June 4, 2026; neither figure describes the Giant Tiger incident.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




