The Goose Creek data breach affected 6,574,121 unique email addresses linked to customers of the online home-fragrance retailer in June 2026. The verified dataset also contained names, phone numbers, physical addresses, and purchase information. Combining contact details with order context can leave users more exposed to personalized fraud attempts.
The incident emerged after some customers reported receiving unsolicited emails that included their personal information. A copy of the dataset was examined and confirmed to contain genuine customer data. Goose Creek was aware of the reports but had not issued a detailed public security advisory as of the source review date. Verification of the dataset must therefore be distinguished from a formal public confirmation by the company.
Verified Types of Data
The verified data classes are email addresses, names, phone numbers, physical addresses, and purchases. Order IDs and customers' total spending were reported within the purchase context. The data appeared to be associated with the store's Shopify environment, but there are no verified technical details explaining the precise access method.
These classes describe the dataset as a whole; they do not mean that every email address was accompanied by a name, phone number, full address, and complete purchase history. The verified sources provide no evidence that passwords, password hashes, full payment-card numbers, or bank account details were included. Users should take the risk seriously without assuming an unsupported financial or password exposure.
Order-Themed Fraud Risk
An attacker who knows a real name, address, order number, or spending amount can make a fake delivery problem, refund, loyalty reward, promotion, or cancellation message appear credible. Accurate personal detail in a message does not prove that the sender represents Goose Creek, a delivery company, or a payment provider. Links that demand urgent action should be checked independently.
Fraudulent messages may request a small redelivery fee, an outstanding payment, an address update, or card details before releasing a refund. If you receive an order warning, type goosecreek.com into the browser yourself instead of using the link in the message and inspect order history from the account. Verify delivery status independently through the carrier's official website or app.
Phishing and Personalized Messages
The combination of email, phone, and physical address can help criminals contact the same person through several channels. An attempt that starts by email may continue by text message or phone call, with a previous order detail used to gain trust. Never disclose a one-time code, password, payment-card detail, or identity document to someone who contacts you unexpectedly.
Check the complete email address and domain rather than the display name. Watch for lookalike domains, shortened links, unexpected attachments, and unusual payment methods. If a caller claims to work for customer service, end the call and contact the retailer again using information published on its official website.
Account and Email Security
Passwords were not confirmed in this dataset, but a Goose Creek password that is reused on another service should still be replaced with a unique one. Enable multi-factor authentication on the primary email account, and regularly review recovery addresses, connected applications, active sessions, and automatic forwarding rules.
If you see an unfamiliar account change or sign-in alert, close active sessions and change the password from a clean device. A password manager makes it easier to create a long, unique password for every service. Removing addresses, phone numbers, or saved payment methods that are no longer needed can reduce the amount of information exposed in a future incident.
Precautions for Address and Phone Data
A physical address and phone number may be used for fake delivery alerts, unwanted calls, and impersonation attempts. Do not confirm personal information to unknown callers or open links sent by text. Setting a separate account password or PIN with the mobile carrier can add protection against fraudulent number transfers.
Contact the relevant carrier or organization directly if you see an unexpected package, delivery-redirection notice, or postal-address change. If family members share the same order account or address, warn them about targeted messages as well. Shared address information may allow a criminal to redirect a message to another person in the household.
How to Interpret a LeakData Match
A Goose Creek match in LeakData means the queried email address is one of the 6,574,121 unique addresses in the verified dataset. It does not prove that all four other data classes were present for that individual, that the current Goose Creek account is compromised, or that payment-card and password information was exposed.
Check the security settings of the email account and the Goose Creek order history first, then separate any reused passwords with unique replacements. Verify messages about orders, deliveries, or refunds through official channels. No match means only that the address was not found in this dataset; it does not guarantee safety from other breaches or from records associated with a different email address.