Carhartt Data Breach Exposes Sensitive Info of 12.9 Million Accounts
A massive cyberattack has left clothing retailer Carhartt reeling after an extortion group, ShinyHunters, published sensitive data from nearly 13 million accounts stolen earlier this month. The breach is one of the most significant to hit a major retail brand in recent memory.
The attack appears to have targeted Carhartt’s Databricks analytics platform, a cloud-based data platform that combines standard business reporting and data storage into a unified architecture. ShinyHunters claimed to have stolen more than 50GB of documents containing customer, employee, and corporate data, including unique email addresses, names, phone numbers, and physical addresses.
According to Have I Been Pwned founder Troy Hunt, the exposed information also includes millions of synthetic records that did not relate to real individuals. However, this does not change the fact that over 12.9 million legitimate accounts have been compromised. Moreover, an additional 15,000 employees with @carhartt.com email addresses were found in the leaked database.
This breach is particularly concerning because it highlights the ease with which attackers can gain access to sensitive data once they obtain valid credentials. In many cases, initial prevention measures may be effective, but once attackers have gained entry, their actions are often not blocked, leaving companies vulnerable to further exploitation.
Carhartt has yet to confirm the extortion group’s claims or issue a statement about the breach. However, it is clear that ShinyHunters has been active in recent months, with links to over a dozen Snowflake customers, third-party integration providers, and hundreds of Salesforce customers. The group’s modus operandi involves stealing sensitive data and then releasing it online unless a ransom demand is met.
The consequences of this breach are far-reaching, not only for Carhartt but also for its customers and employees. In an era where data breaches are becoming increasingly common, it is essential for companies to prioritize cybersecurity measures and ensure that their data storage and analytics platforms are secure against such attacks.
In light of this incident, it is crucial for individuals and organizations alike to take proactive steps in protecting themselves from potential cyber threats. This includes using strong, unique passwords, enabling two-factor authentication, and regularly monitoring account activity for suspicious behavior. By being vigilant and taking preventative measures, we can reduce the risk of falling victim to a data breach like this one.
Source: Bleeping Computer — 2026-08-27