Goose Creek Candle Company Data Breach Exposes Names, Emails, and Physical Addresses

Published: 12 September 2026
Retail data breach illustration
Breach Discovery: June 2026Breach Notification: July 2026

In June 2026, someone claiming unauthorized access to Goose Creek Candle Company’s Shopify store sent stolen customer data, including 6.6 million email addresses, names, phone numbers, addresses, and purchase details, to Have I Been Pwned. The company acknowledged the reports but has not confirmed details. Affected customers should watch for phishing attempts and monitor accounts for suspicious activity.

CompanyGoose Creek Candle Company
IndustryRetail
Data Types ExposedEmail Addresses, Full Names, Phone Numbers, Physical Addresses, Order IDs, Purchase History
People Affected6.6 million unique email addresses
Attack MethodUnauthorized Access
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Goose Creek Candle Company Data Breach?

In June 2026, an unidentified individual began contacting customers of Goose Creek Candle Company by email. The messages claimed the company had a security flaw and that customer data had been stolen. As a result, many customers grew alarmed and started asking questions the company had not yet answered publicly.

Shortly after, the same party sent a large dataset to Have I Been Pwned, a widely used breach-notification service. The data included 6.6 million unique email addresses, along with names, phone numbers, physical addresses, order IDs, and total amounts spent. Evidence suggests the information was pulled from the company’s Shopify-based online store, which is the platform Goose Creek Candle Company uses to process orders.

Because the breach discovery date falls in June 2026, the timeline suggests the attacker had access to this data before reaching out to customers directly. This approach, contacting victims before any official notice went out, is a tactic increasingly used by threat actors to pressure companies into responding quickly.

Have I Been Pwned reached out to Goose Creek Candle Company for confirmation and additional context. However, the company said it could not offer further information at the time of publication. This means the full scope of the intrusion, including how the attacker gained access, remains unclear as of the July 2026 notification date.

Who was affected?

The breach appears to affect customers of Goose Creek Candle Company who placed orders through its online store. Because the exposed data includes order IDs and total spending amounts, it’s likely that anyone who made a purchase through the company’s Shopify platform could be included.

The number of affected individuals hasn’t been publicly disclosed by the company. However, the dataset shared with Have I Been Pwned contained 6.6 million unique email addresses, suggesting a substantial customer base was impacted. Given the online nature of the store, affected customers are likely located throughout the United States and potentially beyond.

At this time, there’s no indication that employees or non-customers were involved in this incident. Still, anyone who has ever placed an order with the company should consider themselves potentially affected until more details emerge.

What Information Was Potentially Exposed?

The data sent to Have I Been Pwned included several categories of personal information tied to customer accounts and purchase history. Below is a summary of what was reportedly exposed in this incident.

  • Email addresses
  • Full names
  • Phone numbers
  • Physical addresses
  • Order IDs
  • Total amount spent (purchase history)

This combination of data creates real risk for affected individuals. For example, attackers can use names, emails, and phone numbers together to craft convincing phishing messages. Because the data also includes purchase history, scammers could reference specific order details to make fraudulent messages look legitimate.

In addition, physical addresses combined with names and contact details raise concerns about targeted scams or even mail-based fraud. While this breach doesn’t appear to include financial account numbers or Social Security numbers, the exposed information is still valuable to scammers running impersonation schemes. As a result, affected customers should stay alert for suspicious emails, texts, or phone calls referencing their Goose Creek Candle Company orders.

What is the company doing?

Goose Creek Candle Company has acknowledged awareness of the reports surrounding this incident. However, as of the most recent update, the company had not provided Have I Been Pwned with further details about the scope or cause of the breach.

It remains unclear whether the company has begun notifying affected customers directly or whether a formal investigation is underway. Because the data appears linked to the company’s Shopify platform, any response will likely involve reviewing account security, access controls, and third-party integrations tied to that system.

Affected customers should watch for official communication from the company in the coming weeks. In the meantime, taking independent protective steps is a smart move, regardless of what additional information becomes available.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Even though this breach doesn’t appear to include financial account details, it’s still wise to check your credit reports regularly. Identity thieves sometimes combine leaked contact information with data from other breaches to open new accounts in your name.

You can request free credit reports from each of the three major credit bureaus. Reviewing them for unfamiliar accounts or inquiries helps you catch fraud early, before it causes lasting damage to your credit history.

Watch for Phishing Attempts

Because your name, email, and phone number may now be in the hands of scammers, phishing attempts are a real concern. Be cautious of emails or texts referencing your Goose Creek Candle Company order, especially ones asking you to click links or confirm personal details.

Instead of clicking on links in unexpected messages, go directly to the company’s official website to check your account status. This simple habit can prevent you from accidentally handing over further personal information to a scammer.

Be Alert to Targeted Scams Using Your Address

Since physical addresses were included in the exposed data, some scammers may attempt mail-based fraud or impersonation schemes. For example, you might receive fake letters claiming to be from the company or a related service.

If you receive suspicious mail or packages referencing a purchase you don’t recognize, don’t respond or provide any additional information. Instead, verify directly with the retailer using contact information from their official website.

Consider a Fraud Alert if You Notice Suspicious Activity

While this breach doesn’t appear to include Social Security numbers, exposed personal details can still be used to attempt account takeovers elsewhere. If you notice unusual activity tied to your name or contact information, placing a fraud alert with one of the credit bureaus adds an extra layer of protection.

A fraud alert requires creditors to verify your identity before opening new accounts in your name. This step is quick, free, and can provide peace of mind while you monitor the situation further.

Update Passwords and Enable Extra Security

Because email addresses were part of the exposed data, it’s a good time to update passwords tied to your Goose Creek Candle Company account and any linked email accounts. Use strong, unique passwords for each account you manage online.

In addition, enabling two-factor authentication wherever possible adds another barrier against unauthorized access. This is especially important if you reuse passwords across multiple websites, since leaked credentials elsewhere could be tested against your other accounts.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

Check other recent data breach notifications →