Food Security

Williams Food Equipment security breach

Pinterest LinkedIn Tumblr

Williams Food Equipment has advised its customers to be on greater alert to more convincing phishing scams because of a security breach last month of a third-party software partner.

On Friday, the Windsor restaurant and home kitchen supplier emailed its customers to advise of the incident in connection with its online store.

“We take the protection of your data very seriously,” read the email.

“We sincerely apologize for any concern or inconvenience this incident may cause.”

While not naming the affected third party, the email notice stressed there was no evidence found that credit card numbers, CVV [Card Verification Value]/security codes, or account passwords were accessed during the breach period of September 13 – 17.

According to the company, an unauthorized party copied several points of data; names, telephone numbers, payment methods and status, as well as transactional information. Email, IP [Internet Protocol], and billing and shipping addresses were also accessed.

The breach has now exposed customers to stronger phishing scam attempts, using purchase information, to craft convincing lures to hook victims.

Williams says cybersecurity experts are now investigating.

The company has not returned a CTV News request for comment.

The new normal

The cyberattack affecting Williams’ customers is the just the latest in a growing number of such incidents, according to Carmi Levy, a technology analyst.

“Unfortunately, this is our new normal,” he said, in an interview with CTV News.

Levy points to legislative solutions as an unlikely salve to the thousands of cuts being caused by continuing security breaches.

“It’s like trying to keep all pollution out of the ocean,” said Levy.

“It’s a really big landscape and there are a lot of potential sources of, in this case, criminal activity and there’s no way for any one entity to stamp them out, let alone one with the resources of a government.”

According to a report by the Office of the Privacy Commissioner of Canada (OPC) released in June, 42 per cent of Canadian organizations had experienced a breach of customer or employee data in the previous 12-month period.

Breaches of personal information reached 20,376,654 Canadian accounts in 2025-26 across 1,147 breach reports — slightly down from the 1,301 breaches reported to the OPC the year prior, however the number of accounts impacted grew by more than 289,000.

The Canadian Anti-Fraud Centre (CAFC) saw more than 112,000 fraud reports involving $704 million in 2025, up from $638 million in 2024. Phishing scams were the fourth most common report of fraud, with 2,869 cases.

As instances of cybercrime become commonplace, Levy says best practices for managing the fallout are also becoming standardized — like offering services to protect and track personal data.

“Williams has done a reasonable job of communicating with customers and other stakeholders in the wake of this event,” said Levy. “What they have not done is share specific information on who that third party was and whether they are going to make things like identity theft protection or credit monitoring services available to victims for a period of time.”

Protecting yourself

When it comes to data breaches, customers are at the mercy of the modern digital retail landscape as sales systems move online, but Levy stresses individuals can reduce their exposure and vulnerability with a little bit of due diligence.

“You have to adopt a mistrust by default perspective,” said Levy.

“In other words, don’t trust anything that hits your email inbox or arises via text or social media direct message. Instead, assume that it’s non-legitimate until it proves otherwise.”

Levy recommends looking for ‘obvious tells’ to verify authenticity of a message, including using the ‘hover method’ to use a computer cursor to hover over email or web addresses for review, as scammers will try to make dubious websites or URL addresses appear authentic.

“Look for additional letters or characters in domain names,” said Levy.

“If you’re not sure, use your own information to contact the vendor directly.”

“When you do follow a link home, make sure that that is the legitimate link of that company. Does it match their domain name? Are the emails coming from a weird looking address? Can you verify that on a map? In other words, look for a street address that can often go a long way toward ensuring that you are, in fact, speaking to who you think you’re speaking to,” said Levy.

In its email to customers, Williams provided a list of best practices to avoid being victimized by phishing scams or other fraudulent attempts to access sensitive information, advising being wary of unexpected communications from the company if they:

Ask you to click a link or open an attachment;Ask you to provide or confirm personal, password or payment information;Ask you to provide a credit card number, CVV/security code;Ask you to make a payment or change payment instructions;Refer to an ‘Order Status’ page, a ‘VIP Loyalty’ offer or coupon, or a problem with an order or refund; orCreate a sense of urgency or threaten consequences if you do not respond.

Levy said each breach can build a treasure trove of information that can be used to target victims with more sophisticated attacks.

“When you add [the Williams breach] to all the information that’s also been liberated in earlier attacks against other providers bought and sold on the dark web, it adds to a growing level of risk that we now face, because now cyber criminals have access to ever more personal data that they can use to customize messages to us and they’re just personalized enough to make us believe maybe they are coming from a legitimate source,” said Levy.

Both the Canadian Centre for Cyber Security and the RCMP provide guides for Canadians to be updated on new and emerging scams as well as guidance to protect against them.