On February 7, 2026, the Canadian golf club Granite Pointe appeared on the public leak site operated by the Clop ransomware group. The club, which operates granitepointe.ca in Nelson, British Columbia, is claimed to have had internal files exfiltrated during a ransomware attack. While the exact number of people whose personal information may have been exposed remains unknown, anyone who has booked a round, joined a tournament, dined at the restaurant, or used the pro shop in recent years could be affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Granitepointe.Ca
Get alerted the next time Granitepointe.Ca files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Granitepointe.Ca’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Clop added granitepointe.ca to its leak site on February 7, 2026. The data consists of internal files exfiltrated after the group deployed ransomware against the club’s systems. No confirmed total of records or specific victim count has been published. The club itself is one of the oldest golf courses in Canada, established in 1919, and serves both local residents and visitors who provide names, addresses, phone numbers, email addresses, and payment details during normal business activities.
Why This Matters for You and Your Family
When a local business like a golf club suffers a breach, the information exposed is rarely limited to corporate documents. Reservation systems, membership lists, event sign-ups, and point-of-sale records often contain the same details you share every time you book a tee time or buy merchandise. Names, contact information, and payment records can be used for identity theft, phishing campaigns, or sold on underground markets. If you or your family members have visited Granite Pointe or similar small businesses, this incident is a reminder that even organizations without national profiles hold data that matters to your daily life.
The Doxxing and Identity-Chain Implications
Credential leaks and internal files from one breach frequently cascade into larger doxxing chains. An email address or phone number taken from the golf club’s systems can be cross-referenced with gaming accounts, social-media handles, or family-shared logins. Once attackers link an online username to a real-world identity and home address, harassment, targeted scams, and account takeovers become easier. Gaming accounts belonging to you or your children are especially vulnerable because the same passwords or recovery emails are often reused across leisure and personal services.