2026 Goose Creek Candle — Shopify customer data; 6.6M emails indexed by HIBP (Jun)
Data compromised
HIBP-indexed: 6.6M unique email addresses, names, phone numbers, physical addresses, order IDs, and total spent; data appears sourced from Shopify instance per HIBP
Technical writeup
Have I Been Pwned verified load — July 15, 2026. In June 2026, a party claiming access to Goose Creek Candle Company customer data emailed some customers alleging a security vulnerability and breach. The dataset was subsequently provided to Have I Been Pwned and contained 6.6 million unique email addresses along with names, phone numbers, physical addresses, order IDs, and total spent fields; HIBP assesses the data likely originated from the company's Shopify e-commerce instance. Goose Creek was aware of customer reports at HIBP publication time but could not supply HIBP with further corporate detail. Troy Hunt noted a large share of affected addresses (about 84%) already appeared in prior HIBP breaches—typical for long-lived retail accounts. BreachHistory indexes the HIBP-attested 6.6M email count; formal company breach FAQ or regulator notice had not been published at catalog time.
Root cause
Third party claiming access to Goose Creek Shopify customer data circulated breach emails to customers in June 2026; dataset loaded by Have I Been Pwned July 15, 2026—company aware but provided limited detail to HIBP at load time