- Cybersecurity Docket
- Posts
- More than 600,000 Canada Goose Customer Records Leaked
More than 600,000 Canada Goose Customer Records Leaked
Plus, Moody’s reports that global investment in data centers will surpass $3 trillion over the next five years; and more

Good morning! Here’s what’s up.

People
Bob Flores, former chief technology officer of the CIA, and Esti Peshin, former vice president and general manager of the cyber division at Israel Aerospace Industries, have joined the advisory board of Cyber 2.0.

Clips ✂️
Canada Goose investigating as hackers leak 600K customer records
ShinyHunters, a well-known data extortion group, claims to have stolen more than 600,000 Canada Goose customer records containing personal and payment-related data.
Canada Goose told BleepingComputer the dataset appears to relate to past customer transactions and that it has not found evidence of a breach of its own systems.
Founded in 1957, Canada Goose is a Toronto-based performance luxury outerwear brand with a global retail footprint and nearly 4,000 employees.
Canada Goose sees no evidence of breach
"Canada Goose is aware that a historical dataset relating to past customer transactions has recently been published online," the company told BleepingComputer.
"At this time, we have no indication of any breach of our own systems. We are currently reviewing the newly released dataset to assess its accuracy and scope and will take any further steps as may be appropriate. To be clear, our review shows no evidence that unmasked financial data was involved. Canada Goose remains committed to protecting customer information."
Why ‘secure-by-design’ systems are non-negotiable in the AI era
Moody’s recently reported that global investment in data centers will surpass $3 trillion over the next five years, driven by AI capacity growth and hyperscaler demand. As big tech companies, banks, and institutional investors pour capital into these projects, data center developers and their financial sponsors must prioritze cybersecurity.
Moody’s said that data center investments made by the six largest U.S. cloud computing providers — Microsoft, Amazon, Alphabet, Oracle, Meta, and CoreWeave — approached $400 billion last year. The firm anticipates that annual global investment will grow by $200 billion over the next two years.
…
In concert, these reports reflect a growing reality: Data centers are strategic, interconnected infrastructure supporting our manufacturing, national security, and communication systems. Cyber disruptions, whether through ransomware, supply-chain compromise, or operational technology (OT) compromises, can cascade beyond a single facility, threatening grid stability, cloud services, economic activity, and public safety.
South Korea’s Gangnam Police Station Loses 2.1 Billion KRW Worth of Bitcoin
On February 16, the Gangnam Police Station in Seoul, South Korea, confirmed that 22 bitcoins—valued at approximately 2.1 billion Korean won at current market rates—were stolen from assets seized during its 2021 investigation.
According to reports, the “cold wallet” device storing these bitcoins remains intact, but the assets within it have been transferred. The incident was uncovered during a nationwide virtual asset security inspection conducted by law enforcement agencies; previously, the Gwangju District Prosecutors’ Office had also lost 320 bitcoins.
South Korean police have launched an investigation into the matter, focusing specifically on the exact method of leakage and whether any internal personnel were involved.
👉The 2.1 billion KRW in stolen bitcoin equals approximately $1.4 million USD.
CISA Adds 11 Known Exploited Vulnerabilities to Catalog
CISA has added 11 new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog over the past week, based on evidence of active exploitation:
CVE-2026-1731 BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
CVE-2024-43468 Microsoft Configuration Manager SQL Injection Vulnerability
CVE-2025-15556 Notepad++ Download of Code Without Integrity Check Vulnerability
CVE-2025-40536 SolarWinds Web Help Desk Security Control Bypass Vulnerability
CVE-2026-20700 Apple Multiple Buffer Overflow Vulnerability
CVE-2026-21510 Microsoft Windows Shell Protection Mechanism Failure Vulnerability
CVE-2026-21513 Microsoft MSHTML Framework Security Feature Bypass Vulnerability
CVE-2026-21514 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
CVE-2026-21519 Microsoft Windows Type Confusion Vulnerability
CVE-2026-21525 Microsoft Windows NULL Pointer Dereference Vulnerability
CVE-2026-21533 Windows Remote Desktop Services Elevation of Privilege Vulnerability
“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA stated.
It strongly urges all organizations “to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice.”
Ransomware attacks increase against IT and food sectors
There were nearly 750 ransomware incidents in the IT sector in 2025, more than double the 300 incidents that the sector experienced in 2024, according to [a new report from the Information Technology Information Sharing and Analysis Center (IT-SAC)]. The group blamed “a strategic pivot toward the IT sector” by ransomware gangs exploiting supply-chain vulnerabilities.
…
The IT sector accounted for nearly 12% of all 6,351 ransomware attacks that the IT-ISAC observed in 2025 using its own data and an analysis of public sources. After manufacturing, commercial facilities and IT, healthcare, financial services and legal organizations rounded out the top six most-targeted industries.
…
In the food and agriculture sector, which experienced 265 ransomware attacks in 2025, Qilin and Akira were responsible for the most intrusions (37 and 36, respectively). They and three other groups accounted for nearly half of all attacks on the sector in 2025.
EU Parliament blocks AI tools over cyber, privacy fears
The European Parliament has disabled AI features on the work devices of lawmakers and their staff over cybersecurity and data protection concerns, according to an internal email seen by POLITICO.
The chamber emailed its members on Monday to say it had disabled "built-in artificial intelligence features" on corporate tablets after its IT department assessed it couldn't guarantee the security of the tools' data.
"Some of these features use cloud services to carry out tasks that could be handled locally, sending data off the device," the Parliament's e-MEP tech support desk said in the email. "As these features continue to evolve and become available on more devices, the full extent of data shared with service providers is still being assessed. Until this is fully clarified, it is considered safer to keep such features disabled."
