A dataset allegedly originating from Golf Canada began circulating via Telegram in mid-2026, exposing roughly 569,000 unique email addresses. The leaked records also contained names, usernames, dates of birth, genders and approximate geographic details such as city, province and postcode. Golf Canada reportedly did not respond to attempts to make contact, and the source of the exposure — whether an unintentionally exposed website feature or an actual security vulnerability — remains unconfirmed.
While no passwords were reported in the exposed data, the combination of email addresses with personal identifiers like dates of birth and location makes affected users prime targets for phishing, social engineering and credential-stuffing attempts. Attackers frequently use such enriched personal data to craft convincing lures or answer security questions.
What to take away: Personal data leaks without passwords still fuel identity-based attacks. Organizations should monitor for exposed employee credentials in breaches like this, and users should stay alert to targeted phishing that references their real personal details.