12.9 million accounts were exposed, according to published reports — and the actors who posted the data said they took more than 50 gigabytes of documents.
Scale: 12.9 million accounts and more than 50 gigabytes of data
Published accounts of the incident quantify the breach as affecting 12.9 million accounts and describe the volume of material taken as “more than 50 gigabytes” of documents. Those figures come from the reporting around the incident; the dataset size and the count of accounts are the primary measures cited by the parties who disclosed the event.
Claimed source of the leak: ShinyHunters; reporting recorded by Have I Been Pwned
The alleged actors responsible for this incident are identified in reporting as ShinyHunters. The data exposure is recorded on the data-breach tracking site Have I Been Pwned (HIBP), which is cited as a source for the information about the exposure. The organization named in the reports—Carhartt—has not publicly confirmed the attack, according to the same reporting.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadContents of the disclosed material: customer, employee and corporate data
The documents said to have been taken include three categories: customer data, employee data and corporate data. The explicitly listed fields within the exposed dataset are names, email addresses, phone numbers and physical addresses. Those four data fields are the specific elements reported as present in the materials posted by the alleged actors and cataloged by the breach-tracking site.
What this means for customers, employees and Carhartt
- Customers: The reporting states that customer data is among the material allegedly taken, and that exposed fields include names, email addresses, phone numbers and physical addresses.
- Employees: Employee data is explicitly listed among the classes of documents the actors say they removed, indicating that staff-related records are part of the claimed disclosure.
- Carhartt (the company): The company named in the reports has not, according to those same reports, issued a confirmation of the breach; the public record at this point rests on the statements attributed to ShinyHunters and on Have I Been Pwned’s listing.
Verification and the remaining questions
The published account rests on two sources: the alleged actors who claimed the theft and the Have I Been Pwned record that logged the disclosure. Beyond the counts and the list of exposed data fields, the organization at the center of the report has not confirmed the incident in the public record tied to these reports. That leaves the central factual threads — the provenance of the documents, the scope of the exposure beyond the stated account count and dataset size, and any response or remediation by the company named — anchored to the actors’ claims and the third-party listing.
The immediate public facts are narrow: 12.9 million accounts affected, “more than 50 gigabytes” of documents claimed taken, categories of data listed as customer, employee and corporate, and specific exposed fields recorded as names, email addresses, phone numbers and physical addresses. The reporting attributes those facts to Have I Been Pwned and the actors identified as ShinyHunters, and it notes that the organization itself has yet to confirm the attack.
Which of those facts will be corroborated or revised when the organization responds is not yet known. The record to date is the set of claims and the listing; the next clear factual step would be a confirmation or statement from the company named that either corroborates or refutes the published account.
https://www.securitymagazine.com/articles/102532-129m-exposed-by-carhartt-data-breach




