One of Canada’s largest retailers, Canadian Tire, recently reported a data breach affecting customers who made online purchases through its e-commerce platforms, says the Canadian Underwriter. On Oct. 2, the retailer discovered unauthorized access to a database containing customer information from Canadian Tire, SportChek, Mark’s/L’Équipeur, and Party City accounts. The exposed data includes names, addresses, emails, birth years, encrypted passwords, and, in some cases, partial credit card numbers similar to those shown on receipts.
Fewer than 150,000 customers also had their full birth dates accessed. Canadian Tire assures that those affected will be contacted directly and offered complimentary credit monitoring through TransUnion Canada. The company emphasized that no Canadian Tire Bank or Triangle Rewards data was compromised, and the breach did not allow unauthorized purchases or account access.
Canadian Tire says that the vulnerability has been resolved and that its websites and systems remain operational and closely monitored by internal teams and external cybersecurity experts. Customers who do not receive an email from TransUnion do not need to take any action, but as Canadian Tire’s platforms are very popular with shoppers it is a good idea for anyone who has made an online purchase to change their password. Even if nothing happened to your personal information, it’s a good reminder for everyone to create strong, unique passwords, enable multi-factor authentication, and report any suspicious financial activity to your bank or local police.
Small and medium enterprises at highest risk … and also the most underprepared
Canadian Tire alone employs more than 10,000 people and operates more than 1,700 retail and gasoline outlets across Canada. It’s a huge business with many resources and reported its data breach right away. This is not the case for many others, and experts have long agreed that cybercrime is often under-reported because of the stigma and embarrassment that can be associated with being scammed.
And (reported) scamming continues to increase at alarming rates. Statistics Canada data show the number of police-reported cybercrimes in the country hit 92,567 last year, up from 65,141 in 2020. Fraud alone made up 46,301 of those crimes, while identity theft accounted for 957 and identity fraud 4,283.
Unfortunately, that data does not show who, exactly, are the victims, but a recent survey by the Insurance Bureau of Canada (IBC) shows that many small and medium-sized enterprise (SME) owners are more than likely underestimating their exposure to cyber threats. Despite cybercrime reaching record global levels, fewer than half (48%) of Canadian SMEs believe they are at risk of a cyber attack or data breach. Quite alarmingly, only 6% strongly agree that their business is vulnerable, even though data from the Business Development Bank of Canada shows that 73% of small businesses have already experienced a cybersecurity incident.
The survey also found that 66% of respondents feel confident their business could withstand a cyber event, yet only 47% report being truly prepared. Fewer than half (48%) have implemented any cyber defences, and just 22% carry cyber insurance, with only 12% holding a stand-alone policy. There is an obvious critical gap between perceived readiness and actual protection.
The survey also revealed growing concern over artificial intelligence (AI) and emerging technologies, with 72% of business owners worried these tools will increase cyber risks, a number up from 65% last year. However, only 45% have employee training or policies to spot AI-driven scams.
As more businesses rely on vendors and cloud services, third-party cyber risks are also growing, leaving owners potentially liable if a partner’s system is compromised. To help address these challenges, IBC offers a free Cyber Insurance Guide.
Business cyber insurance at a glance
Business cyber insurance has significantly advanced over the last few years and shifted from a purely defensive approach to a more proactive, offensive strategy.
Proactive cyber protection focuses on detecting and stopping cyber threats before they happen. The objective is to prevent claims from happening in the first place.
Cyber insurance companies are now using technology that can detect if ransomware has been deployed within an organization but hasn’t yet been activated as well as identify if an organization has been targeted by a phishing attack but the username and password haven’t been used yet. And this can be done without the organization having to install any new technology. Cyber protection companies such as CFC Underwriting are using enhanced algorithms to create an accurate profile of a business in real time. This means processing about 208,000 data points within 10 milliseconds for a typical business by identifying every piece of technology connected to the internet that interacts with the insured in real time. Proactive cyber then considers situational awareness and trends to assess the likelihood of an attack.
Standard business cyber insurance protects the policyholder from:
- Data confidentiality breaches such as the loss of and/or unauthorized access to or disclosure of confidential or personal information.
- Cyber extortion such as a demand for payment while threatening to disrupt your data.
- A technology failure or denial-of-service attack.
Costs associated with loss due to a cyber attack will be covered through cyber insurance, including:
- Payment for legal representation.
- Harm mitigation from a breach, including notifying affected parties and the provision of free credit monitoring.
- The hiring of experts to help prevent further attacks.
- Data restoration.
Coverage for the modern world
Lane’s Insurance is a leading Alberta-based brokerage, providing complete business insurance solutions for owners of companies both large and small. Lane’s works with the province’s most trusted carriers to protect you from today’s advanced digital threats, and much more.
To learn more, or to obtain a quote, please contact us in:







