"Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised," ShinyHunters said after posting an archive it says came from Carhartt.
ShinyHunters' claim and the $3.3 million demand
On August 13, the extortion group ShinyHunters said it stole more than 50GB of documents from the American apparel company Carhartt and attempted to extort the firm for $3.3 million. According to ShinyHunters, the gang released an archive to its dark‑web site after the apparel maker declined to meet its demand. The group published its characterization of the contents as "customer, employee, and corporate data."
ShinyHunters published an interaction in which a company negotiator told the extortionists, "After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," according to the group's account. BleepingComputer reported that a Carhartt spokesperson was not immediately available when contacted for comment.
Have I Been Pwned analysis: 12.9 million accounts and Databricks
After analyzing the 50GB archive, Have I Been Pwned founder Troy Hunt linked the dataset to a compromise of Carhartt's Databricks analytics platform. Hunt concluded the breach affects more than 12.9 million Carhartt accounts and that the exposed information includes unique email addresses, names, phone numbers, and physical addresses.
Hunt also reported finding "millions of synthetic records that did not relate to real individuals and were excluded from the breach" and identified over 15,000 entries with @carhartt.com email addresses inside the leaked database.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildWhat the posted archive reportedly contains
ShinyHunters described the stolen files as encompassing a broad range of records. The gang said the haul contained customer data, employee information, "customer metadata (royalty info)," and "other internal corporate data." The publicly accessible archive on the dark web is the source material used by Have I Been Pwned to map affected accounts.
ShinyHunters' recent campaign patterns and claimed victims
The group behind this publication has been tied by reporting to multiple campaigns affecting cloud data platforms and third‑party integrations. Over the past year, ShinyHunters has been linked to breaches at more than a dozen Snowflake customers and claimed compromises of many third‑party integration providers. The gang also claimed breaches at hundreds of Salesforce customers and stated it stole more than 1.5 billion records in Salesforce Aura and Salesloft Drift campaigns.
More recently, ShinyHunters claimed responsibility for a wave of breaches affecting over 100 organizations after exploiting an Oracle PeopleSoft zero‑day flaw. The group has listed a range of high‑profile organizations among its claimed victims, including the European Commission, Google, Cisco, Match Group, PornHub, Vimeo, Rockstar Games, McGraw Hill, 7‑Eleven, Carnival, Udemy, and Medtronic.
What this means for Carhartt customers, employees, and enterprise security teams
- Carhartt customers and the public: With Have I Been Pwned reporting more than 12.9 million exposed accounts and the leaked archive containing names, email addresses, phone numbers, and physical addresses, individuals tied to Carhartt accounts face increased risk of phishing and identity‑related fraud.
- Carhartt employees: The leaked data reportedly includes more than 15,000 @carhartt.com email addresses. Employees whose corporate addresses appear in the database are likely to become targets for credential‑harvesting and socially engineered attacks tied to corporate internal data.
- Enterprise security teams and cloud platform users: Troy Hunt's linkage of the leak to a Databricks analytics instance underscores the risk to data stored in integrated analytics platforms. As the reporting notes, "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." The Blue Report 2026 — cited in the same reporting — measures defenses technique by technique across 338 million simulations in customer environments, highlighting how adversaries exploit gaps after initial access.
Carhartt, founded in 1889 with manufacturing in Kentucky and Tennessee and more than 3,000 employees in the United States and Europe, has not issued a public confirmation of the breach in the coverage cited here. Meanwhile, the archive remains available on the dark web according to ShinyHunters' posting and Have I Been Pwned's analysis maps millions of affected accounts.
The immediate, verifiable record for this incident is straightforward: ShinyHunters published a 50GB archive it says came from Carhartt after an August 13 attack and a failed $3.3 million extortion demand; Have I Been Pwned tied that archive to a Databricks instance and enumerated more than 12.9 million affected accounts, including thousands of corporate email addresses. Whether Carhartt will confirm the incident, describe remediation steps, or disclose further findings remains to be seen.
Source: BleepingComputer — Carhartt data breach exposes information of 12.9 million accounts




