North Pole Company data breach exposes details on half a million users

A hacker wearing a hoodie sitting at a computer, his face hidden.
(Image credit: Shutterstock / Who is Danny)

  • Threat actor FutureSeeker posts new thread on BreachForums
  • They claim to have stolen sensitive data from The North Pole Company
  • The gift basket firm is yet to respond to the claims

The North Pole Company, a Canadian gift basket delivery service, allegedly suffered a data breach in which half a million customers lost sensitive personal information.

The claim was made on BreachForums, a popular underground community where cybercriminals come to share tools, resources, and experiences, to find partners and plan future attacks.

Cybersecurity researchers from Incogni reported a threat actor using the alias FutureSeeker posted a new thread on BreachForums on January 19, offering a North Pole database to its peers.

No response yet

“Today I have uploaded the NorthPole database for you to download, thanks for reading and enjoy!” reads the thread.

The data compromised in the attack includes email addresses, phone numbers, emails, postal addresses, and full names, of exactly 520,599 people.

The North Pole Company has not yet made an official statement about the alleged breach. We have reached out and will update the article if we hear back.

The North Pole Company is a Canadian gift basket delivery service specializing in Christmas gift baskets featuring gourmet foods, wines, and festive items, aiming to be the leading provider in Canada and the United States.

FutureSeeker is a relatively unknown name in the cybercriminal community. However, if the claims end up being true, that could change. More than half a million active email addresses, together with full names and phone numbers, is more than enough information for phishing, and fraud, leaving users potentially in need of identity theft protection.

To be on the safe side, if you’ve used The North Pole Company’s services in the past couple of years, be wary of incoming email messages and phone numbers, especially from people claiming to be the company’s representatives.

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Security
American National Insurance Company breach data found online
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
Data leak
Top collectibles site leaks personal data of nearly a million users
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring