Back to Feed
BreachesAug 27, 2026

Carhartt data breach exposes information of 12.9 million accounts

ShinyHunters group leaks 12.9 million Carhartt accounts after ransom demand fails.

Summary

The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer Carhartt. The group claimed the attack on August 13, stealing over 50GB of data including customer and employee PII. After Carhartt refused to negotiate a $3.3 million ransom, ShinyHunters released the data on the dark web.

Full text

Carhartt data breach exposes information of 12.9 million accounts By Sergiu Gatlan August 27, 2026 07:10 AM 0 The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and Tennessee and more than 3,000 employees in the United States and Europe. While Carhartt has yet to confirm the extortion group's claims or issue a statement about the breach, ShinyHunters claimed the attack on August 13 and said they allegedly stole more than 50GB of documents containing a wide range of customer, employee, and corporate data. "Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised," the cybercrime gang said. ShinyHunters also released an archive of the allegedly stolen records on its dark web after failing to pressure the apparel giant into paying a $3.3 million ransom demand. "After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," a company negotiator told the extortion gang, according to ShinyHunters. Carhartt entry on ShinyHunters leak site (BleepingComputer) ​After analyzing the 50GB archive released by ShinyHunters on their dark web site, Have I Been Pwned founder Troy Hunt linked the resulting data breach to the compromise of Carhartt's Databricks analytics platform (a cloud-based data platform that combines standard business reporting and data storage into a unified architecture). Hunt added that the data breach affects more than 12.9 million Carhartt accounts, with the exposed information including unique email addresses, names, phone numbers, and physical addresses, as well as "millions of synthetic records that did not relate to real individuals and were excluded from the breach." The Have I Been Pwned founder also found over 15,000 employees with @carhartt.com email addresses in the leaked database. A Carhartt spokesperson was not immediately available for comment when BleepingComputer reached out with more questions regarding the incident. Over the past year, ShinyHunters has also been linked to security breaches at over a dozen Snowflake customers, as well as many third-party integration providers, and claimed breaches at hundreds of Salesforce customers, saying they've stolen more than 1.5 billion records in Salesforce Aura and Salesloft Drift campaigns. Most recently, ShinyHunters claimed responsibility for a series of breaches at more than 100 organizations following data-theft attacks that exploited an Oracle PeopleSoft zero-day flaw. Among the breaches claimed by ShinyHunters are the European Commission, Google, Cisco, online dating giant Match Group, PornHub, video service Vimeo, Rockstar Games, edtech giant McGraw Hill, convenience store chain 7-Eleven, cruise line operator Carnival, online training company Udemy, and medical device maker Medtronic, Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: ATF confirms “major incident” after recent Qilin breach claimsRingCentral data breach exposed info of 1.6 million accountsDentaQuest data breach exposed info of 2.6 million accountsChick-fil-A data breach affects more than 13,000 customersAssuranceAmerica data breach exposes records of 6.9 million drivers

Indicators of Compromise

  • domain — carhartt.com

Entities

ShinyHunters (threat_actor)Databricks (product)Carhartt (vendor)