Carhartt data breach exposes information of 12.9 million accounts

The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.

Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and Tennessee and more than 3,000 employees in the United States and Europe.

While Carhartt has yet to confirm the extortion group’s claims or issue a statement about the breach, ShinyHunters claimed the attack on August 13 and said they allegedly stole more than 50GB of documents containing a wide range of customer, employee, and corporate data.

“Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised,” the cybercrime gang said.

ShinyHunters also released an archive of the allegedly stolen records on its dark web after failing to pressure the apparel giant into paying a $3.3 million ransom demand.

“After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions,” a company negotiator told the extortion gang, according to ShinyHunters.

​After analyzing the 50GB archive released by ShinyHunters on their dark web site, Have I Been Pwned founder Troy Hunt linked the resulting data breach to the compromise of Carhartt’s Databricks analytics platform (a cloud-based data platform that combines standard business reporting and data storage into a unified architecture).

Hunt added that the data breach affects more than 12.9 million Carhartt accounts, with the exposed information including unique email addresses, names, phone numbers, and physical addresses, as well as “millions of synthetic records that did not relate to real individuals and were excluded from the breach.”

The Have I Been Pwned founder also found over 15,000 employees with @carhartt.com email addresses in the leaked database.

A Carhartt spokesperson was not immediately available for comment when BleepingComputer reached out with more questions regarding the incident.

Over the past year, ShinyHunters has also been linked to security breaches at over a dozen Snowflake customers, as well as many third-party integration providers, and claimed breaches at hundreds of Salesforce customers, saying they’ve stolen more than 1.5 billion records in Salesforce Aura and Salesloft Drift campaigns.

Most recently, ShinyHunters claimed responsibility for a series of breaches at more than 100 organizations following data-theft attacks that exploited an Oracle PeopleSoft zero-day flaw.

Among the breaches claimed by ShinyHunters are the European Commission, Google, Cisco, online dating giant Match Group, PornHub, video service Vimeo, Rockstar Games, edtech giant McGraw Hill, convenience store chain 7-Eleven, cruise line operator Carnival, online training company Udemy, and medical device maker Medtronic,

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

ATF confirms “major incident” after recent Qilin breach claims

RingCentral data breach exposed info of 1.6 million accounts

DentaQuest data breach exposed info of 2.6 million accounts

Chick-fil-A data breach affects more than 13,000 customers

AssuranceAmerica data breach exposes records of 6.9 million drivers

Ubiquiti patches three max severity security vulnerabilities

Police arrests dozens of suspects in global cybercrime crackdown

Microsoft Teams now lets admins block external bots from meetings

Protect yourself from data brokers, scammers, and the next data breach with digital identities.

Overdue a password health-check? Audit your Active Directory for free

Discover how least agency keeps your AI tools capable, controlled, and secure.

Discover why encryption and key management are critical for modern business.

Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.

See how AI is reshaping email attacks. Download the 2026 Kaseya Email Security Report.

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.