Loblaw Data Breach: Customer Contact Information Accessed by Hackers
Loblaw Companies Limited has reported a data breach affecting a limited portion of its IT network. Customer contact information, including names, phone numbers, and emails, may have been accessed, while financial and health data remain secure.

Cyberattack at Loblaw Companies Limited exposes customer contact information.
Loblaw Companies Limited has confirmed a data breach after detecting suspicious activity in a segment of its internal IT network.
The company stated that a third-party threat actor accessed limited customer information, but sensitive financial details and personal health data were not affected CISA guidance on data breaches.
Suspicious Activity Detected
Loblaw’s security team identified unusual behavior within a “contained, non-critical” section of its IT infrastructure. In response, the company launched an internal investigation and implemented its cybersecurity response protocols.
The accessed customer data is limited to:
- Names
- Phone numbers
- Email addresses
Loblaw confirmed that PC Financial, its financial services division, was not impacted. No passwords, credit card details, or health information appear to have been compromised.
Immediate Security Measures
To protect customers, Loblaw took immediate actions including:
- Securing the affected network systems
- Logging customers out of digital accounts to prevent unauthorized access
Customers are required to log back into their digital platforms. This precaution ensures account integrity and reduces the risk of misuse if session tokens or account data were exposed.
Although only basic contact information appears compromised, such data can be exploited in phishing campaigns, social engineering attacks, or targeted spam designed to trick users into revealing sensitive credentials.
Ongoing Investigation
Cybersecurity and forensic teams are analyzing affected systems to determine:
- How the attackers gained access
- Whether additional systems were compromised
- Potential attack vectors, which may include compromised credentials, misconfigured systems, or network vulnerabilities
The investigation is ongoing, and Loblaw plans to provide updates as new information emerges.
Customer Guidance
Customers are advised to:
- Monitor for suspicious emails, messages, or phone calls claiming to be from Loblaw
- Verify sources before clicking links or sharing additional personal information
- Report any unusual activity to Loblaw or appropriate authorities
Security professionals warn that even basic personal information can be leveraged in credential harvesting attacks, impersonation scams, or identity theft schemes.
Company Background
Loblaw Companies Limited is one of Canada’s largest private-sector employers, operating a wide network of grocery stores, pharmacies, and digital platforms across the country with over 220,000 employees.
The company emphasized that the investigation is ongoing and further updates will be provided once additional findings become available
Salma Mubarak
Cloud Security & AI Security ContributorSalma is a cloud security architect and AI risk analyst specializing in DevSecOps, SaaS security, and infrastructure protection. She focuses on identifying cloud misconfigurations, AI vulnerabilities, and implementing zero-trust security frameworks for modern organizations.
At MENA Cyber Wire, Salma breaks down complex cybersecurity and AI risk concepts into clear, practical insights for founders, IT managers, and security professionals across the MENA region.