Goose Creek Data Breach (July 2026)
Have I Been Pwned verified 6,574,121 customer records taken from Goose Creek Candle Company, carrying names, email addresses, phone numbers, home addresses and order histories. The company has not published a notice of its own.
- Organization
- Goose Creek
- Sector
- Retail
- Country
- United States, KY
- Incident date
- June 9, 2026
- Disclosed
- July 15, 2026
- Records affected
- 6.6 million
- Attack type
- Undisclosed
- Status
- Confirmed
- Email addresses
- Names
- Phone numbers
- Physical addresses
- Purchases
- The breach date recorded by Have I Been Pwned. At some point in June a party claiming to hold the data emails Goose Creek customers, saying the company has a security vulnerability, per the Have I Been Pwned entry
- Have I Been Pwned publishes the breach with 6,574,121 verified email addresses
- CyberInsider reports the breach and traces the data to the company's Shopify instance
- Techlicious reports that Goose Creek has still issued no statement
What Happened
Goose Creek Candle Company is a family-owned home fragrance business founded in Liberty, Kentucky, in 1998, selling through its own online store and through Walmart.
According to the Have I Been Pwned entry, a party claiming to hold data from the company emailed a number of Goose Creek customers in June 2026, telling them the company had a security vulnerability and had been breached. That party then passed the data to Have I Been Pwned, which published the breach on July 15, 2026 with 6,574,121 unique email addresses in it. The entry records the breach date as June 9, 2026, and says the data appears to have been obtained from the company's Shopify instance.
Goose Creek has not published a notice of its own. Have I Been Pwned says the company was aware of the reports but could not supply any further information at the time the entry went up. The CyberInsider report by Amar Ćemanović, published the same day, found no confirmation and no security advisory from the company, and Suzanne Kantra reported the same absence for Techlicious the following day. No state attorney general filing had surfaced by early September 2026.
The status on this report is confirmed because Have I Been Pwned verified the data itself, not because Goose Creek has acknowledged anything. Nobody has said how the records were taken, so the attack type stays undisclosed. Knowing the data sat in a Shopify store says where it lived, not how someone reached it.
What Was Exposed
The verified data classes on the Have I Been Pwned entry are email addresses, names, phone numbers, physical addresses and purchases. CyberInsider describes that last field as order IDs and each customer's total spending. Both CyberInsider and Techlicious report that passwords and payment card numbers do not appear in the data.
That absence matters. Nothing on this list opens an account or a bank. What the list does is make a scam credible. Whoever holds it already knows your name, the address the candles went to, your phone number, the order number and how much you have spent with the brand over time. The total spent field also sorts the file, so the customers worth the most attention are the easiest ones for a fraudster to pick out first.
What to Do If You Are Affected
There is no credit freeze step on this one, because no Social Security numbers and no card numbers are in the data. The full sequence, including the point at which a freeze does become the right move, is in what to do after a data breach. The tells that separate a fake order email from a real one are in how to spot a phishing email, and what a data breach is covers why a candle retailer holds this much about you in the first place. The Carhartt breach put the same four identity fields into circulation later that summer.
What Is Not Known Yet
How the data left the company, whether Goose Creek will confirm the incident or notify customers directly, and whether any state regulator receives a filing. The published figure is also a count of unique email addresses rather than of people, so the number of individuals affected is a different number and has not been stated. Have I Been Pwned lists five data classes; whether the original file held more than those five has not been said by anyone.
Sources

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.