Customers of Winnipeg's Thermea spa alarmed after notification of …

The parent company of a popular luxury spa in Winnipeg is in hot water after a data breach opened the door for hackers to access a variety of private information from customers. This week, customers who purchased gift certificates from Thermea spa between early November and late February were told in an email that their credit card information may have been compromised, alongside their full names, phone numbers and email and street addresses. Groupe Nordik, the parent company of the spa, said that they learned of the breach in late February, shut down the gift certificate system and hired a third-party firm to investigate.

“We have since enhanced security measures on all Groupe Nordik systems, including the gift certificate system, and will continue to work with the cyber security firm to maximize the protection of our clients’ data,” the email said. Gift certificates that have not been redeemed are still valid, Groupe Nordik said. The appropriate authorities have been notified of the breach and affected customers were encouraged to keep an eye out for any suspicious activity.

Unencrypted credit card info

“What the email didn’t include, though, was any guidance around the risk of identity theft that they have now incurred for me,” John Robins told Radio-Canada in a Wednesday interview.

Robins purchased a Thermea gift certificate with his credit card at a Polo Park kiosk around Christmastime, he said. He has submitted a complaint about the breach to the Office of the Privacy Commissioner. He’s not aware of any fraudulent charges on his credit card, but he’s going through his records again.

Robins was surprised to learn that Thermea saved his credit card information for any amount of time. “I certainly did not think that I was putting myself in that level of risk when I made a simple point-of-sale transaction with Therma.” Gautam Srivastava, a Brandon University professor of computer science who specializes in cybersecurity, said it’s fairly normal for companies to keep the amount of customer information that Thermea did for situations involving marketing and repeat customers.

He said these kinds of data breaches are happening more often, since businesses are prioritizing ease of use.  While paying by the tap of a credit card or phone is speedy and efficient, those practices are not always compatible with good security, Srivastava said. “If you’re looking to encrypt and then decrypt information, there’s time lags there, and so a lot of systems that are built for ease of use find those sorts of things compromised.”

He said Thermea isn’t entirely to blame for the data breach, as malicious attackers often test a number of companies within a specific vicinity in search of system weaknesses. Thermea is a well-loved establishment in Winnipeg, he said, so they won’t necessarily lose all of their business because of the data breach. There are steps Groupe Nordik can take to win back customers, such as keeping their security measures updated and ensuring customers that their information is safe, he said.

Consumers can protect themselves by changing the pins of their bank and credit cards periodically and using strong passwords for their emails, as well as multi-factor authentication or biometric verifications such as fingerprint technology. But at the end of the day, it’s a matter of trust, Srivastava said. “Their brand is going to take a hit for a little bit, but they can take steps in the future starting now to kind of win back some of that trust,” he said.

“When trust is broken in anything, it takes time to win back that trust, and sometimes you never do.” In a statement to Radio-Canada, Groupe Nordik said they hired a third-party cybersecurity firm to investigate the breach and will continue to work with them in the future. “We have since enhanced security measures on all Groupe Nordik systems, including the gift certificate system, and will continue to work with the cyber security firm to maximize the protection of our clients’ data,” the statement said.

Robins said the breach came at an unfortunate time for him and his family, as they lost their house to a fire in January 2022. He said Thermea is a bit of a local institution for Winnipeg and surrounding areas. “I’ve been there many times — really enjoy their service. It’s a real treat to be able to go to a spa.”

But Robins said Thermea will have to win his business back.

“I think giving an email notification that a breach happened is a good first step and I’m grateful for that credit where credit is due,” he said.

“But frankly given the — in my estimation — very weak data practices that this company has been engaged in, I really don’t want to go back to Thermea and jeopardize my data again with that firm.”

hux-health listed on couponmatrix.ukideal-world listed on couponmatrix.uklancome listed on couponmatrix.ukmerlin-pass listed on couponmatrix.ukrural-retreats listed on couponmatrix.ukselect-fashion listed on couponmatrix.uk
hux-health listed on couponmatrix.ukGive yourself a daily edge with HUX supplements – whether you’re aiming for better sleep, brain power or hydration, HUX Health makes it simple by bundling science-backed nutrients into one product. You can purchase a one-off bottle or unlock up to 30% discounts by taking out a subscription, and then add a HUX discount code from Groupon to your order. Whether you need more superfoods in your life or you’re chasing healthier skin and nails, HUX’s high-quality supplements are 100% vegan and the most affordable way to get a variety of nutrients from one little bottle.
ideal-world listed on couponmatrix.ukIn an Ideal World, all the products you need would be in one place. From hoovers to handbags, watches to wigs and gloves to gazebos, if there’s something you need then chances are you’ll find it right here. Shop this remarkable online emporium for less with an Ideal World discount code from Groupon. There’s an endless array of awesome goods on offer from Ideal World, so you’re sure to find something to bring a smile to your face.
lancome listed on couponmatrix.ukIf you’re talking sweet perfume and gorgeous cosmetics, you’re talking Lancôme. As authentic as the French forest its named after, Lancôme offers only the finest fragrances, makeup and cosmetics for true beauty connoisseurs. If you want to feel pampered like royalty without the salon price, stay thrifty and shop with the latest Lancôme discount code from Groupon. When it comes to scents, never accept second best, let it be Lancôme.
merlin-pass listed on couponmatrix.ukWhen it comes to big days out, Merlin are the biggest name in the UK by a country mile: As well as owning top theme parks, they’ve got cultural and educational attractions like Warwick Castle and Sea Life in their portfolio, and the Merlin Pass offers you and your friends and family unlimited entry for a full year. Whether you want high-octane thrills at Alton Towers or Thorpe Park, high altitude viewing platforms at Blackpool or Weymouth or highly atmospheric creepy thrills in the London Dungeon, you’ll always find something that’ll give get the whole family something to get excited about
rural-retreats listed on couponmatrix.ukAt Rural Retreats, you can escape to some of the most beautiful locations in England and Ireland, with the vast majority of properties close to the coast or nestled deep within some of the most stunning countryside areas. With your Rural Retreats voucher code, you can discover the best this country has to offer. Whether you’re looking for a romantic retreat, a break with friends, or a family trip, Rural Retreats have the property for you.
select-fashion listed on couponmatrix.ukSelect Fashion are one of the biggest names in women’s fashion in the UK. Their extensive collection of on-trend styles and clothing make them the perfect place to pick up something special for your wardrobe. With a Select discount code from us you can save on the best in high street fashion, without breaking a sweat. Whether you’re looking for a new pair of jeans or you’re after a dress for date night, Select have got you covered.