Carhartt data breach exposes 12.9 million accounts

The hacking group ShinyHunters published data from 12.9 million Carhartt customer accounts on the dark web after the company rejected a $3.3 million ransom demand. The Carhartt data breach exposed names, email addresses, phone numbers, and postal addresses, according to a report from BleepingComputer.

ShinyHunters added Carhartt to its data leak site after the company declined to pay. “Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised,” the group said in its post. A company negotiator reportedly responded, “After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions.”

What data the Carhartt data breach exposed

Security researcher Troy Hunt, who runs the breach-tracking site HaveIBeenPwned, reviewed the leaked archive and traced it to Carhartt’s Databricks analytics platform. Hunt determined the breach affected 12.9 million accounts, with exposed fields including email addresses, names, phone numbers, and physical addresses. He also noted that the batch contained millions of synthetic records that did not correspond to real people, and he excluded those from his count.

Carhartt operates roughly 60 stores across the United States, employs about 3,000 people, and generates an estimated $1.8 billion in annual revenue. The company has not issued a public statement addressing the scope of the leak beyond its reported refusal to negotiate with ShinyHunters.

ShinyHunters shifts away from ransomware

ShinyHunters has become one of the most active extortion groups currently operating. The gang started as a conventional ransomware operation, but it has since dropped the encryption stage entirely and now focuses on stealing data and threatening to publish it. Its typical method relies on vishing, a form of phone-based social engineering that tricks employees into entering credentials on spoofed login pages.

Once inside a corporate network, the group targets connected software-as-a-service platforms to pull data at scale. ShinyHunters has claimed responsibility for breaches affecting hundreds of Salesforce customers and dozens of Snowflake customers. The Carhartt incident fits that broader pattern rather than standing as an isolated attack.

What customers can do now

Anyone whose information appeared in the leak should watch for phishing attempts that reference their name, address, or phone number. Scammers often use exposed contact details to make follow-up messages look legitimate. An unexpected email or text citing accurate personal information does not confirm the sender is legitimate. Turning on two-factor authentication for any account tied to the exposed email address adds a layer of protection even if a password surfaces in a separate leak later.

  • Watch for phishing emails or texts that reference personal details from the leak.
  • Avoid clicking links in unsolicited messages claiming to be from Carhartt.
  • Consider monitoring accounts for unusual activity in the coming weeks.