The security incident was discovered after Loblaw detected suspicious activity within its infrastructure. According to the company, the hackers compromised a contained, non-critical area of the network.
Despite the breach’s segmentation, the threat actors still managed to access customer records stored in that environment.
Following the initial discovery, Loblaw’s internal investigation confirmed that a criminal third party successfully exfiltrated basic customer contact information.
While the targeted systems did not handle primary operational workloads, they did store personal identifiers.
The compromised customer data includes:
To alleviate immediate security concerns, Loblaw explicitly outlined the limitations of the intrusion.
The threat actors failed to move laterally into highly sensitive databases containing financial or medical records.
According to the company’s forensic investigation, the following information remains secure and uncompromised:
Upon detecting the unauthorized network access, Loblaw immediately triggered its internal security response protocols.
The company has secured the affected network segment and implemented containment measures to protect remaining customer data from further exposure.
As a direct defensive action, Loblaw is forcefully expiring active user sessions across its platforms. All customers will be automatically logged out of their digital accounts.
To regain access to Loblaw’s digital services, users must authenticate and log back in.
While passwords were not compromised during this incident, the exposure of names, email addresses, and phone numbers poses a secondary risk.
Security experts advise affected customers to remain vigilant against potential phishing campaigns and smishing (SMS phishing) attempts.
Threat actors frequently leverage this type of basic contact information to launch targeted social engineering attacks aimed at stealing broader credentials.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post Loblaw Data Breach – Hackers Accessed IT Network and Customer Information appeared first on Cyber Security News.
FORT WAYNE, Ind. (WOWO) — Forecasters say storms across the Upper Midwest could spill into…
INDIANAPOLIS, Ind. (WOWO) — Investigators said Monday 13 people have been sentenced for their roles…
Sony Pictures is back at CinemaCon in 2026, and we're expecting the studio to reveal…
The DJI Mini 4K is an excellent quadcopter drone camera for beginners looking to try…
I've been deeply immersed in the LitRPG genre for years now, but the series that…
Michael Cullen, a Beloit Fire Captain, combines his passion for photography and baseball by serving…
This website uses cookies.