Skip to content
Cyber Security Firms
ConfirmedNon-profit

Golf Canada Data Breach (August 2026)

Have I Been Pwned verified 568,972 email addresses in a Golf Canada dataset that began circulating on Telegram in mid-2026, alongside names, usernames, dates of birth, genders and city-level locations. Golf Canada has not publicly acknowledged the incident.

Disclosed Updated
Organization
Golf Canada
Country
Canada
Incident date
May 14, 2026
Disclosed
August 22, 2026
Records affected
569,000
Attack type
Undisclosed
Status
Confirmed
Data exposed
  • Dates of birth
  • Email addresses
  • Genders
  • Geographic locations
  • Names
  • Usernames
Timeline
  1. The breach date Have I Been Pwned records for the data
  2. Have I Been Pwned loads 568,972 verified email addresses and publishes the entry
  3. TechNadu reports that Golf Canada did not respond to multiple attempts to make contact

What Happened

Golf Canada is the national governing body for golf in Canada and holds the membership and handicap accounts of players at clubs across the country. In mid-2026, a set of user records attributed to it began circulating on Telegram, according to the Have I Been Pwned entry. On August 22, 2026, Have I Been Pwned loaded 568,972 verified unique email addresses from that data, together with names, usernames, dates of birth, genders and approximate geographic locations covering city, province and postal code. The breach date recorded against the data is May 14, 2026.

How the records left Golf Canada is not established. The Have I Been Pwned entry says it remains unclear whether the data was obtained through unintentionally exposed website features or through a security vulnerability, so the attack type on this report is undisclosed rather than a guess.

Golf Canada has not published a statement. Lore Apostol, writing for TechNadu on August 24, 2026, reported that the organization did not respond to multiple attempts to make contact, and that members were surfacing on golf forums saying they had found out through Have I Been Pwned rather than from Golf Canada itself.

What is on the record so far
  1. The breach date Have I Been Pwned records for the data
  2. Have I Been Pwned loads 568,972 verified email addresses
  3. TechNadu reports that Golf Canada has not responded to requests for comment
Golf Canada has added nothing to this record.

What Was Exposed

The verified classes are email addresses, names, usernames, dates of birth, genders and geographic locations. No passwords, no payment details and no scoring or handicap records appear in the Have I Been Pwned classes for this breach.

That set unlocks no account on its own and is unusually good at making an impersonation believable. TechNadu notes that the location data runs to city, province and postal code, which turns what could have been a mailing list into a set of profiles: a real name, a real birth date, the town, and the username the person picked on a golf site.

The dates of birth are the part that does not wash out. A password can be changed and an address can be retired, but a birth date is permanent and is still accepted as an identity check on the phone by banks, insurers and government lines. The usernames matter for a second reason: people reuse them, so a username tied to a confirmed email address hands an attacker two of the three fields a credential stuffing run needs against other sites.

What to Do If You Are Affected

Nobody in this set should expect a letter. The Office of the Privacy Commissioner of Canada tells individuals who receive a breach notification to change their passwords and watch their financial accounts, and warns that fraudsters often wait before using stolen information. Here no notification has arrived, so the prompt has to come from the Have I Been Pwned entry instead. The full sequence is in what to do after a data breach, and the tells in the messages that follow a leak like this one are in what a phishing email looks like.

What Is Not Known Yet

Everything that only Golf Canada can answer: how the data left its systems, whether May 14 is the date of an intrusion or the date the file was assembled, how many of the 568,972 addresses belong to current members, and whether it intends to notify anyone. Under PIPEDA an organization must report a breach to the Privacy Commissioner and notify affected individuals where it is reasonable to believe the breach creates a real risk of significant harm. Whether Golf Canada has made that assessment, and what it concluded, is not on the public record. This report will be updated if a statement or a regulator entry appears.

Sources

  1. Have I Been Pwned: Golf Canada
  2. Lore Apostol, TechNadu, Golf Canada Breach Exposes Nearly 570,000 Accounts, August 24, 2026
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →