“You're not going to believe this, but turns out you can't always take criminals at their word,” said Troy Hunt after analysing a dataset dumped by the group ShinyHunters — and his review cut the apparent scale of the Carhartt incident roughly in half.
Troy Hunt and Have I Been Pwned's tally
Troy Hunt reviewed the dataset advertised by ShinyHunters and uploaded the cleaned results to his Have I Been Pwned (HIBP) service. HIBP reported 12,933,413 accounts believed to be genuine — shorthand in coverage is often given as 12.9 million. HIBP also noted that 83 percent of those accounts had already been gathered up in previous breaches.
What ShinyHunters published and the extortion backdrop
ShinyHunters publicly dumped what it said was 50GB of Carhartt data on August 13. The publication followed an extortion episode in which the group said the retailer had hired “a very unskilled and incompetent negotiator” while the criminals attempted to haggle down a $3.3 million demand. ShinyHunters’ initial public claim implied a larger tally of affected individuals than Hunt’s cleaned number ultimately supported.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildOpenClaw, synthetic TPC-DS injection, and the forensic pruning
Hunt’s first pass used HIBP’s open-source email address extractor, which returned nearly 25 million addresses. He then ran that output through OpenClaw to look for anomalies and synthetic data patterns. OpenClaw — described in the report as an AI used to analyse the contents — flagged an unusual mix of .edu and .org domains for a retailer dataset, a pattern consistent with TPC-DS synthetic data injection.
Examples cited in the dataset included michael.ware@c.edu and michelle.larue@lkvb06fkzsjv.org: first and last names that look real paired with domains that appear random. Manual inspection of those records tied many of the flagged entries to countries such as Benin and to an anomalous count of customers registered in Montenegro that exceeded registrations in the United States, where Carhartt is headquartered. The analysis also found a suspiciously large proportion of customers with birth dates set in the early 1900s — unlikely given the company's described customer profile.
Hunting down these artifacts, OpenClaw pared the apparent number of genuine individuals from roughly 24.8 million to 13.6 million. Hunt then removed additional anomalies — Microsoft 365 duplicate addresses, addresses marked for deactivation, and other clear false positives — and arrived at 12,933,413 accounts that he believed to be genuine.
The composition of the real data and Carhartt's response
The dataset that Hunt treats as genuine contains names, email addresses, phone numbers, and physical addresses. According to the report, Carhartt did not respond to a request for comment on Hunt’s findings and is yet to comment on the breach anywhere publicly.
What this means for technologists, enterprises, and users
- Technologists and security teams: Analysts will focus on the synthetic-data problem Hunt documented — distinguishing injected TPC-DS-style records from legitimate customer data — and on procedures to validate publicized breach counts before treating them as accurate.
- Affected enterprises and procurement leaders: The episode underscores the risks of relying on headline figures from threat actors during ransom or extortion negotiations; organisations will likely scrutinise negotiation processes and the provenance of data before engaging or disclosing.
- End users and the general public: Individuals whose details appear in HIBP should note that HIBP’s 12,933,413-account figure represents Hunt’s cleaned set; HIBP also reports most of those accounts (83 percent) were already present in prior breaches, implying possible re-use of exposed details.
Hunt’s central admonition — that reporters and the public “take headline numbers with a grain of salt unless you're confident in the processes of those making the claims” — is the practical takeaway. In this case, a visible digital forensic workflow reduced an initial, noisy 25-million-ish extraction to a narrower set of roughly 12.9 million accounts believed to be real, while identifying clear signs of synthetic padding and duplicate or deactivated addresses.
Whether further investigation or a public statement from Carhartt will change the count remains to be seen. For now, the incident is a reminder that raw dumps and extortion claims deserve scrutiny before they enter the public record.
Original reporting: The Register — Carhartt data breach affects 12.9M, half of what ShinyHunters claimed




