Goose Creek Candle Company is facing a reported data breach after an unknown party emailed some customers claiming the retailer had a security vulnerability and that its data had been compromised. The exposed dataset was later submitted to Have I Been Pwned, which listed the incident as affecting approximately 6.6 million unique email addresses tied to Goose Creek customer records.
The leaked information reportedly includes names, phone numbers, physical addresses, order IDs, and purchase-related details such as total spent. Reporting indicates the data appears to have been obtained from Goose Creek’s Shopify instance. Goose Creek acknowledged awareness of the reports, but no additional details had been provided to Have I Been Pwned at the time of publication.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Goose Creek Candle Company acknowledged that it was aware of the reports about the incident, but had not provided Have I Been Pwned with additional information at the time of publication.
The exposed dataset was later provided to Have I Been Pwned and reportedly contained about 6.6 million unique email addresses, plus names, phone numbers, physical addresses, order IDs, and total-spent or purchase-related information. The data appears to have been obtained from Goose Creek Candle Company's Shopify instance.
In June 2026, a party claiming to have access to Goose Creek Candle Company data emailed a number of the company's customers, alleging the company had a security vulnerability and had suffered a data breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.