Data breach hits 44 big Canada Post shippers, exposing nearly 1M customers

Cyberattack on EDI provider compromises shipping manifest data of postal carrier’s parcel customers

Canada Post says a cyberattack on an EDI provider compromised data from major parcel customers. (Photo: Canada Post)

Canada Post said on Wednesday that a cyberattack and data breach on an electronic data interchange (EDI) supplier has compromised information from 44 of its large parcel business customers, affecting nearly 1 million recipients. 

The attack on Ontario-based Commport Communications compromised the shipping manifest data of the customers. Canada Post, Canada’s government-run postal carrier, did not identify the customers. 

About 950,000 recipients were impacted by the breach, Canada Post said. The vast majority of the data, 97%, consisted of names and addresses, with 3% including email addresses or phone numbers. 

Canada Post said Commport notified it of the breach a week ago on May 19. The postal carrier said it is investigating the attack.  

Before the latest disclosure, Canada Post said the EDI provider had notified it of a “potential ransomware issue” in November. An investigation found “no evidence to suggest any customer data had been compromised at that time,” the postal carrier said. 

Canada Post did not explicitly link that “potential ransomware issue” with the newly disclosed data breach. However, it is notoriously difficult to determine the extent of data breaches after ransomware attacks, particularly in cases where the hackers cover their tracks. 

Canada Post uses Commport to manage shipping manifest data of its large parcel customers.  

Another Canada-based EDI provider, Faxinating Solutions, was targeted in a ransomware attack earlier in the spring.

EDIs, in place since the 1960s, offer standardized communications platforms for business-to-business communication. They are used extensively in the transportation and logistics industry to communicate key shipping data. 

Commport did not immediately respond to FreightWaves’ request for comment. 

Click for more FreightWaves articles by Nate Tabak.

Upcoming FreightWaves Events
Fraud & Security

Freight Fraud Symposium

Double brokering. AI deepfakes. Identity theft. Freight fraud is an existential threat to the industry. Get ahead of it.

May 20, 2026
Rock & Roll Hall of Fame • Cleveland, OH
Register Now
AI & Technology

Supply Chain AI Symposium

Past the hype. Join operators, founders, and enterprise leaders figuring out how to deploy AI in supply chain.

July 15, 2026
The Old Post Office • Chicago, IL
Register Now
Rail & Policy

Future of Rail Symposium

Reshoring is rewriting freight demand. Join shippers, rail executives, and government officials to shape the next decade.

July 28, 2026
The Signal at Chattanooga Choo Choo • Chattanooga, TN
Register Now
Fraud & Security Freight Fraud Symposium May 20 • Cleveland, OH

Double brokering. AI deepfakes. Identity theft. Freight fraud is an existential threat to the industry. Get ahead of it.

Rock & Roll Hall of Fame • Cleveland, OH Register Now
AI & Technology Supply Chain AI Symposium Jul 15 • Chicago, IL

Past the hype. Join operators, founders, and enterprise leaders figuring out how to deploy AI in supply chain.

The Old Post Office • Chicago, IL Register Now
Rail & Policy Future of Rail Symposium Jul 28 • Chattanooga, TN

Reshoring is rewriting freight demand. Join shippers, rail executives, and government officials to shape the next decade.

The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now