A threat actor claims to have obtained more than 6.5 million customer records associated with weight management and wellness company GOLO and is offering the alleged database for sale.
The listing, published September 23, 2026, describes the material as a newly extracted Shopify customer database covering consumers in the United States and Canada. The actor claims the information was obtained through compromised Shopify API credentials.
BreachNews has not independently verified the authenticity or origin of the complete dataset, the claimed record count or the method allegedly used to obtain it. GOLO had not issued any public statement confirming a breach at time of publication.
Actor claims 6.5 million Shopify records
The threat actor claims the database contains 6,500,040 records associated with GOLO customers and describes the material as originating from 2026.
According to the listing, the records can contain first and last names, primary and alternate email addresses, phone numbers, customer tags and metadata, along with internal customer identifiers.
The actor published a sample containing records structured with Shopify-style customer identifiers. BreachNews is not reproducing the sample because it contains personal information belonging to purported customers.
The sample does not establish that 6.5 million unique people are affected. Individual customers could potentially appear more than once, while the sample itself contains records that appear to be test or placeholder accounts. The claimed figure should therefore be treated as a record count rather than a confirmed number of affected individuals.
No passwords, payment card numbers or banking information were included among the fields the actor claims are present in the database.
Compromised Shopify API credentials blamed
The actor claims the data was extracted using compromised Shopify API credentials, but has not provided enough technical evidence to independently establish that access method.
GOLO’s website currently uses Shopify Payments for payment processing, confirming that Shopify technology is part of the company’s e-commerce environment.
The Shopify-formatted identifiers visible in the alleged sample are also consistent with data originating from a Shopify environment, but their presence alone does not prove that GOLO’s Shopify account or API credentials were compromised.
It is also unclear how the credentials were allegedly obtained. The actor has not publicly described whether the claimed access resulted from credential theft, a compromised application, an exposed token, social engineering or another intrusion method.
There is currently no evidence indicating that Shopify itself suffered a platform-wide security breach. If the actor’s account is accurate, the claim instead points to credentials associated with GOLO’s individual e-commerce environment.
GOLO collects customer and account information
GOLO sells weight management, dietary supplement, food and wellness products directly to consumers through its online platform.
The company’s current privacy policy states that GOLO collects personal information from customers and users through purchases, its website, mobile application and other interactions with the company.
GOLO also operates the myGOLO service, which provides customers with online resources and account functionality.
The threat actor’s listing does not claim that health information from myGOLO, order histories or other potentially more sensitive information is included in the alleged database.
That distinction is important because GOLO operates in the health and wellness market. Based on the information currently available, there is no evidence that the alleged dataset contains medical records, health conditions, weight information or other consumer health data.
Contact information creates phishing risk
If authentic, the combination of names, email addresses, phone numbers and customer metadata could create opportunities for targeted phishing and social engineering.
Attackers could potentially impersonate GOLO or related services and use knowledge that a person is a customer to make fraudulent emails, text messages or calls appear more convincing.
The alleged exposure of customer identifiers and metadata could provide additional context for those attacks depending on what information the metadata contains.
However, the current claim does not indicate that account passwords or payment card information were stolen. GOLO states that it uses Shopify Payments to securely handle payment card information.
Scope remains unconfirmed
The breach claim currently rests on the threat actor’s listing and a limited sample rather than confirmation from GOLO or an independent forensic investigation.
The sample’s structure provides some indicators consistent with Shopify customer data, but it cannot establish the provenance, freshness or completeness of the alleged database.
The claimed 6.5 million records also should not be interpreted as 6.5 million confirmed GOLO customers without further evidence. Duplicate records, historical entries, test accounts and other non-customer records could affect the total.
GOLO had not issued any public statement confirming unauthorized access or a customer data breach at time of publication.
BreachNews will update this report if GOLO confirms an incident, additional evidence establishes the origin of the database or further information clarifies the number of individuals potentially affected.











