US candle retailer Goose Creek Candle Company had 6.6 million customer records exposed, according to Have I Been Pwned. The data appears to have come from the company's Shopify environment and includes names, phone numbers, mailing addresses, order numbers and total spend. Passwords and full card numbers were not part of it. The real risk is subtler: Have I Been Pwned notes that while 84% of the email addresses were already known from earlier breaches, the addresses, phone numbers and order histories were not previously exposed in bulk — and they're precise enough to make a phishing message referencing a genuine order very convincing. EU customers who ordered from them can still exercise their GDPR rights.
After a breach: the part most people skip
A leaked email and phone number don't just sit in one dump — data brokers buy breach data, merge it with public records, and resell it. That's why the spam calls and phishing texts keep coming months later. Deleting your data from the breached company is only the first step; getting it out of the broker network is what actually stops the follow-on damage.