BTC$84,521-0.54% LTC$68.72+1.12% XMR$536.90-2.07%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Aug 27, 2026 · 2 min read · Original story

Carhartt data breach exposes information of 12.9 million accounts

Carhartt data breach exposes information of 12.9 million accounts

The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.

Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and Tennessee and more than 3,000 employees in the United States and Europe.

While Carhartt has yet to confirm the extortion group's claims or issue a statement about the breach, ShinyHunters claimed the attack on August 13 and said they allegedly stole more than 50GB of documents containing a wide range of customer, employee, and corporate data.

"Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised," the cybercrime gang said.

ShinyHunters also released an archive of the allegedly stolen records on its dark web after failing to pressure the apparel giant into paying a $3.3 million ransom demand.

"After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," a company negotiator told the extortion gang, according to ShinyHunters.

Carhartt entry on ShinyHunters leak site (BleepingComputer)

​After analyzing the 50GB archive released by ShinyHunters on their dark web site, Have I Been Pwned founder Troy Hunt linked the resulting data breach to the compromise of Carhartt's Databricks analytics platform (a cloud-based data platform that combines standard business reporting and data storage into a unified architecture).

Hunt added that the data breach affects more than 12.9 million Carhartt accounts, with the exposed information including unique email addresses, names, phone numbers, and physical addresses, as well as "millions of synthetic records that did not relate to real individuals and were excluded from the breach."

The Have I Been Pwned founder also found over 15,000 employees with @carhartt.com email addresses in the leaked database.

A Carhartt spokesperson was not immediately available for comment when BleepingComputer reached out with more questions regarding the incident.

Over the past year, ShinyHunters has also been linked to security breaches at over a dozen Snowflake customers, as well as many third-party integration providers, and claimed breaches at hundreds of Salesforce customers, saying they've stolen more than 1.5 billion records in Salesforce Aura and Salesloft Drift campaigns.

Most recently, ShinyHunters claimed responsibility for a series of breaches at more than 100 organizations following data-theft attacks that exploited an Oracle PeopleSoft zero-day flaw.

Among the breaches claimed by ShinyHunters are the European Commission, Google, Cisco, online dating giant Match Group, PornHub, video service Vimeo, Rockstar Games, edtech giant McGraw Hill, convenience store chain 7-Eleven, cruise line operator Carnival, online training company Udemy, and medical device maker Medtronic,

References in this story

  1. Hackmanac (@H4ckmanac) on X x.com 🚨Cyber Alert ‼️ 🇺🇸US - 𝗖𝗮𝗿𝗵𝗮𝗿𝘁𝘁 ShinyHunters hacking group claims to have compromised Carhartt and allegedly stolen more than 50 GB of compressed data containing millions of customer records, employee information…
  2. The AI Security Starter Pack (Free Download) | Wiz wiz.io Wiz is the unified cloud security platform with prevention and response capabilities, enabling security and development teams to build faster and more securely.
  3. Have I Been Pwned: Carhartt Data Breach haveibeenpwned.com In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email…
  4. A Cautionary Tale About Data Breach Claims, Verification and Carhartt www.troyhunt.com You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here…
  5. Latest Salesforce news www.bleepingcomputer.com The latest news about Salesforce
  6. ShinyHunters claims ongoing Salesforce Aura data theft attacks www.google.com Salesforce is warning customers that hackers are targeting websites with misconfigured Experience Cloud platforms that give guest users access to more data than intended. However, the ShinyHunters extortion gang claims…
  7. Latest Salesloft Drift news www.bleepingcomputer.com The latest news about Salesloft Drift
  8. Oracle mitigates PeopleSoft zero-day exploited in data theft attacks www.bleepingcomputer.com Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks.
  9. CERT-EU: European Commission hack exposes data of 30 EU entities www.bleepingcomputer.com The European Union's Cybersecurity Service (CERT-EU) has attributed the European Commission cloud hack to the TeamPCP threat group, saying the resulting breach exposed the data of at least 29 other Union entities.
  10. Google suffers data breach in ongoing Salesforce data theft attacks www.bleepingcomputer.com Google is the latest company to suffer a data breach in an ongoing wave of Salesforce CRM data theft attacks conducted by the ShinyHunters extortion group.
  11. Cisco discloses data breach impacting Cisco.com user accounts www.bleepingcomputer.com Cisco has disclosed that cybercriminals stole the basic profile information of users registered on Cisco.com following a voice phishing (vishing) attack that targeted a company representative.
  12. Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match www.bleepingcomputer.com Match Group, the owner of multiple popular online dating services, Tinder, Match.com, Meetic, OkCupid, and Hinge, confirmed a cybersecurity incident that compromised user data.
  13. PornHub extorted after hackers steal Premium member activity data www.bleepingcomputer.com Adult video platform PornHub is being extorted by the ShinyHunters extortion gang after the search and watch history of its Premium members was reportedly stolen in a recent Mixpanel data breach.
  14. Video service Vimeo confirms Anodot breach exposed user data www.bleepingcomputer.com Vimeo has disclosed that data belonging to some of its customers and users has been accessed without authorization following the recent breach at the Anodot data anomaly detection company.
  15. Stolen Rockstar Games analytics data leaked by extortion gang www.bleepingcomputer.com Rockstar Games has suffered a data breach linked to a recent security incident at Anodot, with the ShinyHunters extortion gang now leaking the stolen data on its data leak site.
  16. Data breach at edtech giant McGraw Hill affects 13.5 million accounts www.bleepingcomputer.com The ShinyHunters extortion group has leaked data from 13.5 million McGraw Hill user accounts, stolen after breaching the company's Salesforce environment earlier this month.
  17. 7-Eleven data breach exposes personal information of 185,000 people www.bleepingcomputer.com The ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I…
  18. Medtronic confirms breach after hackers claim 9 million records theft www.bleepingcomputer.com Medical device giant Medtronic disclosed last week that hackers breached its network and accessed data in "certain corporate IT systems."

Guides related to this story

← Back to all news