Golf Canada Data Breach (August 2026)
Have I Been Pwned verified 568,972 email addresses in a Golf Canada dataset that began circulating on Telegram in mid-2026, alongside names, usernames, dates of birth, genders and city-level locations. Golf Canada has not publicly acknowledged the incident.
- Organization
- Golf Canada
- Sector
- Non-profit
- Country
- Canada
- Incident date
- May 14, 2026
- Disclosed
- August 22, 2026
- Records affected
- 569,000
- Attack type
- Undisclosed
- Status
- Confirmed
- Dates of birth
- Email addresses
- Genders
- Geographic locations
- Names
- Usernames
- The breach date Have I Been Pwned records for the data
- Have I Been Pwned loads 568,972 verified email addresses and publishes the entry
- TechNadu reports that Golf Canada did not respond to multiple attempts to make contact
What Happened
Golf Canada is the national governing body for golf in Canada and holds the membership and handicap accounts of players at clubs across the country. In mid-2026, a set of user records attributed to it began circulating on Telegram, according to the Have I Been Pwned entry. On August 22, 2026, Have I Been Pwned loaded 568,972 verified unique email addresses from that data, together with names, usernames, dates of birth, genders and approximate geographic locations covering city, province and postal code. The breach date recorded against the data is May 14, 2026.
How the records left Golf Canada is not established. The Have I Been Pwned entry says it remains unclear whether the data was obtained through unintentionally exposed website features or through a security vulnerability, so the attack type on this report is undisclosed rather than a guess.
Golf Canada has not published a statement. Lore Apostol, writing for TechNadu on August 24, 2026, reported that the organization did not respond to multiple attempts to make contact, and that members were surfacing on golf forums saying they had found out through Have I Been Pwned rather than from Golf Canada itself.
- The breach date Have I Been Pwned records for the data
- Have I Been Pwned loads 568,972 verified email addresses
- TechNadu reports that Golf Canada has not responded to requests for comment
What Was Exposed
The verified classes are email addresses, names, usernames, dates of birth, genders and geographic locations. No passwords, no payment details and no scoring or handicap records appear in the Have I Been Pwned classes for this breach.
That set unlocks no account on its own and is unusually good at making an impersonation believable. TechNadu notes that the location data runs to city, province and postal code, which turns what could have been a mailing list into a set of profiles: a real name, a real birth date, the town, and the username the person picked on a golf site.
The dates of birth are the part that does not wash out. A password can be changed and an address can be retired, but a birth date is permanent and is still accepted as an identity check on the phone by banks, insurers and government lines. The usernames matter for a second reason: people reuse them, so a username tied to a confirmed email address hands an attacker two of the three fields a credential stuffing run needs against other sites.
What to Do If You Are Affected
Nobody in this set should expect a letter. The Office of the Privacy Commissioner of Canada tells individuals who receive a breach notification to change their passwords and watch their financial accounts, and warns that fraudsters often wait before using stolen information. Here no notification has arrived, so the prompt has to come from the Have I Been Pwned entry instead. The full sequence is in what to do after a data breach, and the tells in the messages that follow a leak like this one are in what a phishing email looks like.
What Is Not Known Yet
Everything that only Golf Canada can answer: how the data left its systems, whether May 14 is the date of an intrusion or the date the file was assembled, how many of the 568,972 addresses belong to current members, and whether it intends to notify anyone. Under PIPEDA an organization must report a breach to the Privacy Commissioner and notify affected individuals where it is reasonable to believe the breach creates a real risk of significant harm. Whether Golf Canada has made that assessment, and what it concluded, is not on the public record. This report will be updated if a statement or a regulator entry appears.
Sources

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.