It took nearly a year for an Ontario woman to build a PC Optimum balance worth hundreds of dollars. According to a new report, it took only minutes for someone else to drain it.
Mandy Campbell of Kincardine discovered in late July that more than 700,000 points had been redeemed at a Shoppers Drug Mart in Oakville, roughly three hours from where she lived. The transactions immediately raised questions about how someone had gained access to her rewards account, particularly after Loblaw disclosed a separate customer-data breach earlier in 2026. Loblaw, however, says its investigation reached a different conclusion: Campbell’s personal email account had been accessed without authorization, and the March breach was not responsible. The case shows how a loyalty balance accumulated purchase by purchase can become a meaningful target once an online account is compromised.
Nearly a Year of Points Disappeared Within Minutes
Campbell had spent roughly nine months accumulating hundreds of thousands of PC Optimum points before discovering they had suddenly been redeemed. CityNews reported that her account history showed the transactions taking place at a Shoppers Drug Mart in Oakville. The timestamps indicated the points were used within a short period, while Campbell said she was nowhere near the store. Kincardine and Oakville are separated by a significant drive, making the location of the redemptions an immediate warning sign.
The scale of the transactions made the incident more than an irritating account problem. CityNews reported that the person responsible obtained more than $1,000 worth of products using Campbell’s points. She believed the digital barcode associated with her PC Optimum account had been used during the redemptions. For someone who had spent months deliberately building a balance, the experience was similar to opening a savings envelope and discovering that someone had emptied it while she was somewhere else entirely.
Loblaw Says the Customer’s Email Account Was Compromised
The most important finding came from Loblaw after it reviewed Campbell’s case. The company said the unauthorized redemption was associated with unauthorized access to her personal email account rather than a breach of Loblaw’s own systems. That distinction matters because Campbell had initially questioned whether a cybersecurity incident disclosed by Loblaw earlier in the year might have played a role. The company explicitly rejected that connection after examining what happened.
A compromised email account can create problems far beyond the inbox itself. Email addresses are commonly used as usernames and as part of account-recovery processes across online services. Canada’s Centre for Cyber Security therefore recommends protecting email accounts with unique passwords and multi-factor authentication whenever possible. Its guidance notes that MFA can help prevent unauthorized entry even when a password has already been compromised. Campbell’s experience is a reminder that protecting a loyalty account can depend partly on protecting the email account connected to it.
Loblaw Had Disclosed a Separate Data Breach in March
Campbell’s concern about Loblaw’s systems did not emerge in a vacuum. On March 10, 2026, Loblaw disclosed that a criminal third party had accessed a contained, non-critical portion of its IT network. The company said some basic customer information—including names, phone numbers and email addresses—was exposed. As part of its response, Loblaw refreshed active customer sessions, meaning customers had to sign back into affected Loblaw digital services.
The company said its investigation indicated that passwords, health information and payment-card information were not compromised. It also said PC Financial was not affected. When Campbell’s case surfaced months later, Loblaw reiterated those findings and said the March incident had not caused her unauthorized points redemption. That does not make the earlier breach irrelevant to customers concerned about digital privacy, but the available evidence does not establish a connection between the two events. In Campbell’s specific case, Loblaw maintains that unauthorized access began outside its network, with her email.
700,000 Points Represent a Meaningful Store Balance
PC Optimum points may not look like conventional currency, but a large balance has considerable purchasing power. Under the program’s standard redemption structure, 10,000 points are worth $10 in rewards at participating stores. On that basis, 700,000 points ordinarily represent $700 in base redemption value. The program allows members to spend points across participating Loblaw businesses, turning balances accumulated gradually on groceries, pharmacy purchases and promotional offers into future purchasing power.
CityNews nevertheless reported that more than $1,000 worth of products were obtained during the unauthorized redemptions in Campbell’s case. The report did not provide enough transaction detail to fully reconcile that retail value with the program’s standard points conversion, so it would be inappropriate to assume exactly how the total was reached. What is clear is the size of the account involved. The federal Privacy Commissioner has described PC Optimum as a program with more than 17 million members across Canada, making security around loyalty balances relevant to a substantial portion of Canadian households.
PC Optimum Accounts Have Been Targeted Before
The idea of criminals targeting loyalty points is not new. In 2017, before the current PC Optimum program was created, Loblaw acknowledged unauthorized access to PC Plus accounts after usernames and passwords obtained elsewhere were used against its website. The incident was an early example of credential stuffing, where attackers test previously exposed login combinations against different services in hopes that customers reused the same credentials.
Security concerns continued after PC Optimum launched in February 2018. An Alberta privacy regulator later documented automated attacks against Loblaw web properties, including PC Optimum, in which bots attempted to authenticate customer login credentials. There have also been individual complaints about missing or improperly redeemed points since then. In 2023, CityNews reported that one Ontario customer spent more than six months trying to have 30,000 points restored after they were mistakenly redeemed through an account issue in another province. These incidents differ technically, but together they demonstrate why accumulated loyalty points should not be treated as inconsequential.
Campbell’s Points Were Eventually Restored
Campbell reported the fraudulent transactions to Loblaw quickly, but the resolution was not immediate. When she initially contacted CityNews, Loblaw was still investigating and the missing points had not been returned. She worried that recovering a balance that had taken months to build could turn into a lengthy series of calls and emails, particularly because the transaction records already showed redemptions occurring far from where she was located.
The situation changed after CityNews’s Speakers Corner contacted Loblaw. Within hours of that outreach, Campbell’s missing points were restored to her account. She also filed a police report because the transactions involved more than $1,000 worth of merchandise, and CityNews reported that the police investigation remained underway when its story was published on August 10. Restoration of the points removed the immediate financial impact for Campbell, but it did not erase the larger concern: a digital rewards account she had spent most of a year building had apparently been accessed and drained before she could stop it.
One App Setting Can Reduce the Redemption Risk
Campbell has since highlighted a PC Optimum feature that can make a stolen account less useful to someone attempting to spend its points. The app allows members to disable redemption while continuing to collect points. Redemption can then be turned back on when the legitimate account holder is ready to use the balance. In practical terms, it creates an additional barrier between an accumulated points balance and an unauthorized checkout transaction.
There are broader precautions worth taking as well. Canada’s Centre for Cyber Security recommends using different passwords for different accounts rather than recycling the same credentials. A reputable password manager can make unique passwords easier to maintain. More importantly in a case involving alleged email compromise, multi-factor authentication should be activated on the email account whenever the provider supports it. Customers with large loyalty balances can also review transaction activity periodically instead of discovering unauthorized redemptions much later. None of these measures guarantees that fraud will never occur, but each removes an easy opportunity an attacker might otherwise exploit.
The Bigger Issue Is Confidence in Digital Loyalty Programs
PC Optimum operates on a massive scale. The Office of the Privacy Commissioner of Canada reported in March that the program had more than 17 million members, meaning even unusual account problems can attract attention because so many Canadians use the platform. The same federal investigation was separate from Campbell’s theft and dealt with account deletion and data retention, but it found that Loblaw had taken an unreasonable amount of time to address some deletion requests and privacy inquiries. Loblaw subsequently made procedural improvements and agreed to additional measures concerning retained information.
That privacy finding, Loblaw’s March cybersecurity disclosure and Campbell’s later points theft involve different issues and should not be conflated. Together, however, they illustrate the increasingly important role digital trust plays in loyalty programs. Customers are no longer storing only coupons on plastic cards. They are accumulating balances potentially worth hundreds or thousands of dollars inside accounts connected to personal information, purchase histories and digital identities. Campbell got her points back. The lesson from how quickly they disappeared may last considerably longer.