Avril Supermarché Santé, the Quebec-based health food chain, was listed on the Black Basta ransomware leak site on December 11, 2024. The extortion group claims to have exfiltrated roughly 550 GB of internal files from the company, which operates multiple stores across the province and collects personal information from both employees and customers.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch avril.ca
Get alerted the next time avril.ca files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about avril.ca’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The Black Basta leak site lists Avril.ca as a victim and states that data was taken during a ransomware attack. The posting indicates the stolen material includes financial data and accounting records, human resources files, personal employee documents, and additional internal directories. The disclosure does not quantify how many individuals are affected, nor does it specify whether customer records were included. The total claimed volume is listed as approximately 550 GB. No ransom demand figure or payment deadline appears in the public listing.
Why This Matters for You and Your Family
If you have shopped at an Avril store, worked there, or had a family member employed by the chain, your personal information may now sit in an attacker-controlled archive. Employee files often contain full names, dates of birth, Social Insurance Numbers, home addresses, and banking details for direct deposit. Even basic customer loyalty or purchase records can link your email, phone number, and spending habits to a real-world identity. Once such data leaves the company’s control, it travels quickly through underground markets and can fuel identity theft, tax fraud, or targeted phishing for years.
Doxxing and Identity-Chain Risks
Leaked HR and financial documents create long identity chains. An attacker who obtains your name, address, and employee ID from Avril can cross-reference it with data from previous breaches to build a complete profile. This profile often includes linked email accounts, reused passwords, and phone numbers that appear in credential dumps. The same information can expose family members when household addresses or shared email addresses are present. Gaming accounts belonging to children are especially vulnerable because parents frequently reuse credentials across work, shopping, and entertainment services; a single leak can cascade into account takeovers that reveal even more personal details.