Fair Vote Canada Data Breach (2024)
If you are a customer of Fair Vote Canada, here’s what’s now in circulation.
In March 2024, the Canadian national citizens' campaign for proportional representation Fair Vote Canada suffered a data breach. The incident was attributed to "a well-meaning volunteer" who inadvertently exposed data from 2020 which included 134k unique email addresses, names, physical addresses, phone numbers and, for some individuals, date and amount of a donation.
Fair Vote Canada customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
On March 2, 2024, Fair Vote Canada appeared in a fresh listing on Have I Been Pwned, confirming that data belonging to 134,000 individuals had been exposed. The Canadian organization, which campaigns for proportional representation, suffered an accidental breach traced to a well-meaning volunteer who inadvertently made a 2020 dataset publicly accessible. The records contained names, email addresses, phone numbers, physical addresses, and, for some donors, details of political contributions.
Reported Details from the Disclosure
The primary listing on Have I Been Pwned states that the exposed information includes email addresses, names, phone numbers, physical addresses, and political donation records showing date and amount for a subset of the 134K unique email addresses. The breach originated from data collected in 2020 and was not the result of a sophisticated cyber attack but rather a configuration error by an internal volunteer. The disclosure does not indicate that passwords, financial account numbers, or government-issued ID numbers were included. Fair Vote Canada has not published its own detailed notification quantifying exact overlap between records or confirming the precise mechanism of exposure beyond the volunteer’s role.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Why This Matters for You and Your Family
If you signed a petition, volunteered, or made even a small donation to Fair Vote Canada around 2020, your contact details and possibly your donation history are now available to anyone who knows where to look. This is not abstract risk. Names paired with home addresses and phone numbers allow spammers, aggressive telemarketers, or worse to reach you and your household directly. Political donation records can reveal your personal views on electoral reform, information that some people or organizations might use to profile, target, or harass you. Because the breach sat unnoticed for years, the window for misuse has already been open far longer than most victims realize.
The Doxxing and Identity-Chain Risks
Once an address and phone number are paired with an email, attackers can quickly link your identity across dozens of other platforms. A single donation record can be cross-referenced with voter rolls, social-media profiles, or public campaign contribution databases, creating a persistent dossier. These chains often spread to family members when shared addresses or phone numbers appear. Children’s gaming accounts registered with the same family email suddenly become reachable targets for grooming or account theft because the underlying parent’s identity has been doxxed. The longer the data circulates, the more likely it is to be bundled into larger datasets sold on underground forums.
What to Do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real-world identity, then use the cleanup of Warden to remove what you can.
- Rotate any password you used for the Fair Vote Canada site or related political platforms and enable 2FA through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next exposure of your data is caught in hours instead of years.
- Cover the household with DoxxScan family protection that extends to dependents and children’s gaming accounts that often chain back to the same address or parent email.
- Let remediation specialists handle ongoing takedown requests for any data-broker listings that surface from this breach.
The incident shows how even well-intentioned organizations can expose supporters to long-term privacy harm through simple mistakes. A forward-looking approach means treating every old political or nonprofit signup as a potential leak source and maintaining active visibility into where your information travels. DoxxScan by GalaxyWarden delivers that visibility through continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that includes children’s gaming accounts vulnerable to credential-stuffing attacks that cascade from incidents like this one.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…